<div class="container">
    <h1>Security update for apache-sshd, jpgpj</h1>

    <table class="table table-striped table-bordered">
        <tbody>
        <tr>
            <th>Announcement ID:</th>
            <td>SUSE-SU-2026:2472-1</td>
        </tr>
        <tr>
            <th>Release Date:</th>
            <td>2026-06-19T13:41:45Z</td>
        </tr>
        
        <tr>
            <th>Rating:</th>
            <td>important</td>
        </tr>
        <tr>
            <th>References:</th>
            <td>
                <ul>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1239551">bsc#1239551</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1267018">bsc#1267018</a>
                        </li>
                    
                    
                </ul>
            </td>
        </tr>
        
            <tr>
                <th>
                    Cross-References:
                </th>
                <td>
                    <ul>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2020-36843.html">CVE-2020-36843</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-48827.html">CVE-2026-48827</a>
                        </li>
                    
                    </ul>
                </td>
            </tr>
            <tr>
                <th>CVSS scores:</th>
                <td>
                    <ul class="list-group">
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2020-36843</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.7</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2020-36843</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2020-36843</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">4.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-48827</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-48827</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-48827</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</span>
                            </li>
                        
                    </ul>
                </td>
            </tr>
        
        <tr>
            <th>Affected Products:</th>
            <td>
                <ul class="list-group">
                    
                        <li class="list-group-item">Development Tools Module 15-SP7</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Desktop 15 SP7</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing LTSS 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing LTSS 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Real Time 15 SP7</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP4 LTSS</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP5 LTSS</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP6</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP6 LTSS</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP7</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP6</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP7</li>
                    
                </ul>
            </td>
        </tr>
        </tbody>
    </table>

    <p>An update that solves two vulnerabilities can now be installed.</p>

    


    
        <h2>Description:</h2>
    
    <p>This update for apache-sshd, jpgpj fixes the following issues</p>
<ul>
<li>CVE-2020-36843: no check performed on scalar to avoid signature malleability (bsc#1239551).</li>
<li>CVE-2026-48827: Apache MINA SSHD: Path traversal in org.apache.sshd: sshd-git (bsc#1267018).</li>
</ul>
<p>Changes for jpgpj:</p>
<ul>
<li>Initial packaging with v1.3</li>
</ul>
<p>Changes for apache-sshd:</p>
<ul>
<li>Update to upstream version 2.18.0</li>
<li>Bug Fixes</li>
<li>GH-743 Ensure the Java ServiceLoader use a singleton
 SftpFileSystemProvider</li>
<li>GH-879 Close SSH channel gracefully on exception in port
 forwarding</li>
<li>Security: Improve handling of repository paths in sshd-git.
 Resolves CVE-2026-48827, bsc#1267018</li>
<li>New Features</li>
<li>GH-892 Align handling certificates without principals with
 OpenSSH 10.3</li>
<li>Update to upstream version 2.17.1</li>
<li>Changes</li>
<li>GH-875 Use Apache Parent POM 36</li>
<li>Update to upstream version 2.17.0</li>
<li>GH-469, SSHD-897 Fix duplicate character echo with interactive
 shells</li>
<li>GH-721 SSH client: schedule session timeout checks on demand
 only</li>
<li>GH-807 Handle "verified" flag for sk-* keys</li>
<li>GH-809 Fix server-side authentication for FIDO/U2F sk-* keys
 with flags in authorized_keys</li>
<li>GH-827 Don&#x27;t fail on invalid known_hosts lines; log and skip
 them</li>
<li>GH-830 EC public keys: let Bouncy Castle generate X.509
 encodings with the curve OID as algorithm parameter</li>
<li>GH-855 SFTP: use a single SftpClient per SftpFileSystem</li>
<li>GH-856 Fix using ed25519 with BC-FIPS</li>
<li>GH-861 SFTP client: prevent sending zero-length writes in
 SftpOutputStreamAsync</li>
<li>SSHD-1348 Fix zero-length SFTP reads</li>
<li>SSHD-1349 Bump PMD to 7.20.0 to avoid StackOverflowError when
 compiling on Java 26-ea</li>
<li>GH-814 Include a fix for CVE-2020-36843 (bsc#1239551) in
 optional dependency net.i2p.crypto:eddsa:0.3.0: perform the
 missing range check in Apache MINA SSHD before delegating to
 the signature verification in net.i2p.crypto:eddsa:0.3.0.
 This means that using net.i2p.crypto:eddsa:0.3.0 in Apache
 MINA SSHD is safe despite that CVE in the dependency.</li>
<li>GH-865 replace %h in HostName SSH config</li>
<li>Update to upstream version 2.16.0</li>
<li>Changes of version 2.16.0</li>
<li>bugfix: fix cert auth failed bug</li>
<li>GH-664: Skip MAC negotiation if an AEAD cipher was negotiated</li>
<li>GH-663: Fix a race in IoSession creation</li>
<li>Also test sshd-mina using mina-core 2.2.4</li>
<li>ScpShell fixes; SFTP append mode for buggy servers</li>
<li>fix sources.jar Reproducible Builds issue</li>
<li>GH-700: Fix race in AbstractCloseable.doCloseImmediately()</li>
<li>GH-705: Make ChannelToPortHandler accessible to user code</li>
<li>GH-709: Handle keep-alive channel messages sent by an old
 OpenSSH server</li>
<li>GH-727: supply default port for proxyJump if no
 HostConfigEntry</li>
<li>GH-733: Fix SftpRemotePathChannel.transferTo</li>
<li>GH-725: Added commandTimeoutMillis in executeRemoteCommand</li>
<li>GH-774: Fix WritePendingException</li>
<li>
<h1>771 Avoid NoClassDefFoundError:</h1>
 net/i2p/crypto/eddsa/EdDSAPublicKey</li>
<li>GH-516: Fix filesystem-id parsing in getFileSystem(URI)</li>
<li>GH-754: Don&#x27;t close DefaultForwarder on bind error</li>
<li>Close repository after usage in GitPackCommand</li>
<li>Trigger ClientChannelEvent.Timeout and
 ClientSessionEvent.TIMEOUT independently to host&#x27;s program
 cycle times</li>
<li>Changes of version 2.15.0</li>
<li>GH-618: Fix reading an OpenSshCertificate from a Buffer</li>
<li>Add interface to configure details of JGit&#x27;s pack
 implementation</li>
<li>ML-KEM key exchanges using Bouncy Castle 1.79</li>
<li>GH-628: Fix reading directories with trailing blanks in the
 name</li>
<li>GH-626: Enable Streaming.Async for ChannelDirectTcpip</li>
<li>Sftp server &#x27;ls&#x27; command timeout</li>
<li>GH-636: Handle unknown key types in known_hosts</li>
<li>GH-643: provide interfaces for caching file attributes on
 paths</li>
<li>Bouncy Castle EdDSA / Ed25519 Support</li>
<li>Abstract revoked key handling in KnownHostsServerKeyVerifier</li>
<li>Fix an incompletely interpolated dependency with maven 4.0.0-rc-4</li>
<li>Fix wrong invocation of xmvn-subst</li>
<li>Updated to upstream version 2.14.0</li>
<li>Changes in version 2.14.0</li>
<li>GH-524 Performance improvements</li>
<li>GH-533 Fix multi-step authentication</li>
<li>GH-582 Fix filtering in NamedFactory</li>
<li>GH-587 Prevent NullPointerExceptionon closed channel in
 NettyIoSession</li>
<li>GH-590 Better support for FIPS</li>
<li>GH-597 Pass on Charset in
 ClientSession.executeRemoteCommand()</li>
<li>New utility methods SftpClient.put(Path localFile, String
 remoteFileName) and SftpClient.put(InputStream in, String
 remoteFileName) facilitate SFTP file uploading.</li>
<li>GH-590 Better support for FIPS
 Besides fixing a bug with bc-fips (the RandomGenerator class
 exists in normal Bouncy Castle, but not in the FIPS version,
 but Apache MINA sshd referenced it even if only bc-fips was
 present), support was improved for running in an environment
 restricted by FIPS.
 There is a new system property
 org.apache.sshd.security.fipsEnabled. If set to true, a number
 of crypto-algorithms not approved by FIPS 140 are disabled:</li>
<li>key exchange methods sntrup761x25519-sha512,
 sntrup761x25519-sha512@openssh.com, curve25519-sha256,
 curve25519-sha256@libssh.org, curve448-sha512.</li>
<li>the chacha20-poly1305 cipher.</li>
<li>the bcrypt KDF used in encrypted private key files in
 OpenSSH format.</li>
<li>all ed25519 keys and signatures.
 Additionally, the new "SunJCEWrapper" SecurityProviderRegistrar
 (see below) and the EdDSASecurityProviderRegistrar are
 disabled, and the BouncyCastleScurityProviderRegistrar looks
 only for the "BCFIPS" security provider, not for the normal
 "BC" provider.
 If the system property is not set to true, FIPS mode can be
 enabled programmatically by calling SecurityUtils.setFipsMode()
 before any other call to Apache MINA sshd.</li>
<li>Potential compatibility issues</li>
<li>New security provider registrar
 There is a new SecurityProviderRegistrar that is registered
 by default if there is a SunJCE security provider. It uses
 the AES and HmacSHA* implementations from SunJCE even if
 Bouncy Castle is also registered. SunJCE has native
 implementations, whereas Bouncy Castle may not.
 The new registrar has the name "SunJCEWrapper" and can be
 configured like any other registrar. It can be disabled via
 the system property
 org.apache.sshd.security.provider.SunJCEWrapper.enabled=false.
 It is also disabled in FIPS mode (see above).
 The methods NamedFactory.setupBuiltinFactories(boolean
 ignoreUnsupported, ...) and
 NamedFactory.setupTransformedFactories(boolean
 ignoreUnsupported, ...) had a bug that gave the
 "ignoreUnsupported" parameter actually the meaning of
 "include unsupported".
 This was fixed in this release, but existing code calling
 these or one of the following methods:
 ~ BaseBuilder.setUpDefaultMacs(boolean ignoreUnsupported)
 ~ BaseBuilder.setUpDefaultCiphers(boolean ignoreUnsupported)
 ~ ClientBuilder.setUpDefaultCompressionFactories(boolean
 ignoreUnsupported)
 ~ ClientBuilder.setUpDefaultKeyExchanges(boolean
 ~ ClientBuilder.setUpDefaultSignatureFactories(boolean
 ~ ServerBuilder.setUpDefaultCompressionFactories(boolean
 ~ ServerBuilder.setUpDefaultKeyExchanges(boolean
 ~ ServerBuilder.setUpDefaultSignatureFactories(boolean
 ~ any of the methods starting with
 SshConfigFileReader.configure
 ~ SshClientConfigFileReader.configure(...)
 ~ SshServerConfigFileReader.configure(...)
 should be reviewed:
 ~ if the method is called with parameter value true, the
 result will no longer include unsupported algorithms.
 Formerly it wrongly did.
 ~ if the method is called with parameter value false, the
 result may include unsupported algorithms. Formerly it
 did not.
 So if existing code used parameter value false to ensure it
 never got unsupported algorithms, change it to true.</li>
<li>Major Code Re-factoring</li>
<li>JDK requirements
 ~ GH-536 The project now requires JDK 17 at build time, while
 the target runtime still remains unchanged to support JDK
 8.</li>
<li>Changes in version 2.13.2</li>
<li>What&#x27;s Changed</li>
<li>GH-525: Fix sntrup761x25519-sha512 by @tomaswolf in #528</li>
<li>Changes in version 2.13.1</li>
<li>This release does not contain any code changes. It is solely
 to rectify the issue that the 2.13.0 release encountered
 during the release process, where the source jars were not
 created.</li>
<li>Changes in version 2.13.0</li>
<li>GH-318: Handle cascaded proxy jumps by @tomaswolf in #512</li>
<li>GH-427: Read initial ACK on channel open prior to direct
 stream upload & close streams prior to exit code handling by
 @TerraNibble in #464</li>
<li>GH-455: ensure BaseCipher.update() fulfills the contract by
 @tomaswolf in #463</li>
<li>GH-470: Synchronize not thread safe
 java.security.KeyPairGenerator.generateKe... by
 @zakharovsergey1000 in #467</li>
<li>GH-476: Fix Android detection false negative by @wh0</li>
<li>GH-475: Switch uses of JSch library to the
 com.github.mwiede:jsch fork by @Alex-Vol-Amz</li>
<li>GH-472: change client start condition in sshd-spring-sftp by
 @alwaystom</li>
<li>GH-489: sftp readdir: determine file type from longname by
 @tomaswolf in #491</li>
<li>GH-486: Add missing U2F {ed25519,ecdsa}-sk public key
 equality methods by @lf-</li>
<li>SSHD-1237 Handle keep-alive channel requests by @tomaswolf in
 #492</li>
<li>GH-494: Nio2Session improvements by @evgeny-pasynkov</li>
<li>GH-468: Handle excess data in SFTP read requests by
 @tomaswolf in #495</li>
<li>GH-498: Implement the "sntrup761x25519-sha512@openssh.com"
 KEX method by @tomaswolf</li>
<li>GH-500: SftpFileSystemProvider: close SftpClient on exception
 by @tomaswolf in #501</li>
<li>GH-504: Pass reason to sessionNegotiationEnd by @duco-lw in
 #505</li>
<li>GH-461: Fix heartbeats with wantReply=true by @tomaswolf in
 #507</li>
<li>GH-493: Fix arcfour128 and arcfour256 ciphers (regression in
 2.2.0)</li>
<li>GH-509: SFTP v[456] client: validate attribute flags</li>
<li>GH-510: Fix class name in BuiltinIoServiceFactoryFactories
 (regression in 2.6.0)</li>
<li>sntrup761x25519-sha512@openssh.com Key Exchange
 The key exchange method sntrup761x25519-sha512@openssh.com is
 now available if the Bouncy Castle library is available.
 This uses a post-quantum key encapsulation method (KEM) to
 make key exchange future-proof against quantum attacks.
 More information can be found in IETF Memo Secure Shell (SSH)
 Key Exchange Method Using Hybrid Streamlined NTRU Prime
 sntrup761 and X25519 with SHA-512: sntrup761x25519-sha512.</li>
<li>Behavioral changes and enhancements
 ~ GH-318 Handle cascaded proxy jumps
 Proxy jumps can be configured via host configuration
 entries in two ways. First, proxies can be chained directly
 by specifiying several proxies in one ProxyJump directive:
 Host target
 Hostname somewhere.example.org
 User some_user
 IdentityFile ~/.ssh/some_id
 ProxyJump jumphost2, jumphost1
 Host jumphost1
 Hostname jumphost1@example.org
 User jumphost1_user
 IdentityFile ~/.ssh/id_jumphost1
 Host jumphost2
 Hostname jumphost2@example.org
 User jumphost2_user
 IdentityFile ~/.ssh/id_jumphost2
 Connecting to server target will first connect to
 jumphost1, then tunnel through to jumphost2, and finally
 tunnel to target. So the full connection will be
 client->jumphost1->jumphost2->target.
 Such proxy jump chains were already supported in Apache
 MINA SSHD.
 Newly, Apache MINA SSHD also supports cascading proxy
 jumps, so a configuration like
 ProxyJump jumphost2
 ProxyJump jumphost1
 also works now, and produces the same connection
 It is possible to mis-configure such proxy jump cascades to
 have loops. (For instance, if host jumphost1 in the above
 example had a ProxyJump jumphost2 directive.) To catch such
 misconfigurations, Apache MINA SSHD imposes an upper limit
 on the total number of proxy jumps in a connection. An
 exception is thrown if there are more than
 CoreModuleProperties.MAX_PROXY_JUMPS proxy jumps in a
 connection. The default value of this property is 10. Most
 real uses of proxy jumps will have one or maybe two proxy
 jumps only.
 ~ GH-461 Fix heartbeats with wantReply=true
 The client-side heartbeat mechanism has been updated. Such
 heartbeats are configured via the
 CoreModuleProperties.HEARTBEAT_INTERVAL property. If this
 interval is > 0, heartbeats are sent to the server.
 Previously these heartbeats could also be configured with a
 CoreModuleProperties.HEARTBEAT_REPLY_WAIT timeout. If the
 timeout was <= 0, the client would just send heartbeat
 requests without expecting any answers. If the timeout was
 > 0, the client would send requests with a flag indicating
 that the server should reply. The client would then wait
 for the specified duration for the reply and would
 terminate the connection if none was received.
 This mechanism could cause trouble if the timeout was
 fairly long and the server was slow to respond. A timeout
 longer than the interval could also delay subsequent
 heartbeats.
 The CoreModuleProperties.HEARTBEAT_REPLY_WAIT property is
 now deprecated.
 There is a new configuration property
 CoreModuleProperties.HEARTBEAT_NO_REPLY_MAX instead. It
 defines a limit for the number of heartbeats sent without
 receiving a reply before a session is terminated. If the
 value is <= 0, the client still sends heartbeats without
 expecting any reply. If the value is > 0, the client will
 request a reply from the server for each heartbeat message,
 and it will terminate the connection if the number of
 unanswered heartbeats reaches
 CoreModuleProperties.HEARTBEAT_NO_REPLY_MAX.
 This new way to configure heartbeats aligns with the
 OpenSSH configuration options ServerAliveInterval and
 ServerAliveCountMax.
 For compatibility with older configurations that explicitly
 define CoreModuleProperties.HEARTBEAT_REPLY_WAIT, the new
 code maps this to the new configuration (but only if
 CoreModuleProperties.HEARTBEAT_INTERVAL > 0 and the new
 property CoreModuleProperties.HEARTBEAT_NO_REPLY_MAX has
 not been set) by setting
 CoreModuleProperties.HEARTBEAT_NO_REPLY_MAX to
 = CoreModuleProperties.HEARTBEAT_REPLY_WAIT <= 0:
 CoreModuleProperties.HEARTBEAT_NO_REPLY_MAX = 0
 = otherwise: (CoreModuleProperties.HEARTBEAT_REPLY_WAIT /
 CoreModuleProperties.HEARTBEAT_INTERVAL) + 1.
 ~ GH-468 SFTP: validate length of data received: must not be
 more than requested
 SFTP read operations now check the amount of data they get
 back. If it&#x27;s more than requested an exception is thrown.
 SFTP servers must never return more data than the client
 requested, but it appears that there are some that do so.
 If property SftpModuleProperties.TOLERATE_EXCESS_DATA is
 set to true, a warning is logged and such excess data is
 silently discarded.</li>
<li>AES-CBC ciphers removed from server&#x27;s defaults
 The AES-CBC ciphers aes128-cbc, aes192-cbc, and aes256-cbc
 have been removed from the default list of cipher algorithms
 that a server proposes in the key exchange. OpenSSH has
 removed these cipher algorithms from the server proposal in
 2014, and has removed them from the client proposal in 2017.
 The cipher implementations still exist but they are not
 enabled by default. Existing code that explicitly sets the
 cipher factories is unaffected. Code that relies on the
 default settings will newly create a server that does not
 support the CBC-mode ciphers. To enable the CBC-mode ciphers,
 one can use for instance
 SshServer server = ServerBuilder.builder()
 ...
 .cipherFactories(BuiltinFactory.setUpFactories(false,
 BaseBuilder.DEFAULT_CIPHERS_PREFERENCES));
 .build();
 For the SSH client, the CBC ciphers are still enabled by
 default to facilitate connecting to legacy servers. We plan
 to remove the CBC ciphers from the client&#x27;s defaults in the
 next release.</li>
<li>Changes in version 2.12.1</li>
<li>GH-458 Singleton thread pool for kex message handler flushing</li>
<li>SSHD-1338 Restore binary compatibility with 2.9.2</li>
<li>Fix link by @swiedenfeld in #454</li>
<li>SSHD-1338 Restore binary compatibility with 2.9.2 by @gnodet
 in #456</li>
<li>Use a singleton threadpool for kex message handler flushing
 by @FliegenKLATSCH in #459</li>
<li>Enable module: sshd-openpgp</li>
<li>Add an "extras" flavour to build without cycles all modules we
 can</li>
</ul>



    

    <h2>Patch Instructions:</h2>
    <p>
        To install this SUSE  update use the SUSE recommended
        installation methods like YaST online_update or "zypper patch".<br/>

        Alternatively you can run the command listed for your product:
    </p>
    <ul class="list-group">
        
            <li class="list-group-item">
                SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                Development Tools Module 15-SP7
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server 15 SP4 LTSS
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server 15 SP5 LTSS
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server 15 SP6 LTSS
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server for SAP Applications 15 SP4
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server for SAP Applications 15 SP5
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2472=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server for SAP Applications 15 SP6
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2472=1</code>
                    
                    
                
            </li>
        
    </ul>

    <h2>Package List:</h2>
    <ul>
        
            
                <li>
                    Development Tools Module 15-SP7 (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
                    <ul>
                        
                            <li>apache-sshd-2.18.0-150200.5.11.1</li>
                        
                            <li>jpgpj-1.3-150200.5.3.1</li>
                        
                    </ul>
                </li>
            
        
    </ul>

    
        <h2>References:</h2>
        <ul>
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2020-36843.html">https://www.suse.com/security/cve/CVE-2020-36843.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-48827.html">https://www.suse.com/security/cve/CVE-2026-48827.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1239551">https://bugzilla.suse.com/show_bug.cgi?id=1239551</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1267018">https://bugzilla.suse.com/show_bug.cgi?id=1267018</a>
                    </li>
                
            
        </ul>
    
</div>