Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

openSUSE Leap 16.0 sdbootutil Important Threat CVE-2026-25701

opensuse
Calendar Grey June 3, 2026
Dist Opensuse Esm H88
An important security update for openSUSE sdbootutil addresses CVE-2026-25701 and includes 11 additional fixes.
An update that solves one vulnerability and has 11 bug fixes can now be installed.

Description

This update for sdbootutil fixes the following issues

Security issue:

- CVE-2026-25701: use of fixed directory /tmp/pcrlock.d.back in sdbootutil-update-predictions.service (bsc#1258241).

Non security issues:

Update to version 1+git20260506.25d47bf:

- TPM based system does not auto-unlock encryption (bsc#1257612).

- openQA test fails in reboot_after_installation - sdbootutil does not honor timeout set by user

(bsc#1258944).

- Installation with Systemd-boot fails when Turkish language is selected (bsc#1253652).

- armv7 installer requires sdbootutil and shim on armv7 (bsc#1254865).

- sdbootutil default entry not updated after update from 20250411 to 20250522 (bsc#1243889).

- sdbootutil: consistent naming conventions used for key/pin ? (bsc#1252871).

- UPDATE_NVRAM is NO when BLS bootloader is used (bsc#1247952).

- Use tmpfiles.d for /var directories (jsc#PED-14900).

- yast reports "Cannot enroll authentication" during fresh install of tumbleweed (bsc#1256775).

Patch...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

sdbootutil-1+git20260506.25d47bf-160000.1.1

sdbootutil-bash-completion-1+git20260506.25d47bf-160000.1.1

sdbootutil-dracut-measure-pcr-1+git20260506.25d47bf-160000.1.1

sdbootutil-enroll-1+git20260506.25d47bf-160000.1.1

sdbootutil-jeos-firstboot-enroll-1+git20260506.25d47bf-160000.1.1

sdbootutil-kernel-install-1+git20260506.25d47bf-160000.1.1

sdbootutil-snapper-1+git20260506.25d47bf-160000.1.1

sdbootutil-tukit-1+git20260506.25d47bf-160000.1.1

References

* bsc#1243889

* bsc#1247952

* bsc#1252871

* bsc#1253652

* bsc#1254317

* bsc#1254534

* bsc#1254865

* bsc#1256775

* bsc#1257612

* bsc#1258241

* bsc#1258944

References:

* https://www.suse.com/security/cve/CVE-2026-25701.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20878-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here