Alerts This Week
Warning Icon 1 357
Alerts This Week
Warning Icon 1 357

openSUSE sdbootutil Important Patch CVE-2026-25701 Security Update

opensuse
Calendar Grey June 3, 2026
Dist Opensuse Esm H88
An important security update for openSUSE sdbootutil fixes one issue and addresses 11 bugs. Act promptly to secure your system.
An update that solves one vulnerability and has 11 bug fixes can now be installed.

Description

This update for sdbootutil fixes the following issues

Security issue:

- CVE-2026-25701: use of fixed directory /tmp/pcrlock.d.back in sdbootutil-update-predictions.service (bsc#1258241).

Non security issues:

Update to version 1+git20260506.25d47bf:

- TPM based system does not auto-unlock encryption (bsc#1257612).

- openQA test fails in reboot_after_installation - sdbootutil does not honor timeout set by user

(bsc#1258944).

- Installation with Systemd-boot fails when Turkish language is selected (bsc#1253652).

- armv7 installer requires sdbootutil and shim on armv7 (bsc#1254865).

- sdbootutil default entry not updated after update from 20250411 to 20250522 (bsc#1243889).

- sdbootutil: consistent naming conventions used for key/pin ? (bsc#1252871).

- UPDATE_NVRAM is NO when BLS bootloader is used (bsc#1247952).

- Use tmpfiles.d for /var directories (jsc#PED-14900).

- yast reports "Cannot enroll authentication" during fresh install of tumbleweed (bsc#1256775).

Patch...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

sdbootutil-1+git20260506.25d47bf-160000.1.1

sdbootutil-bash-completion-1+git20260506.25d47bf-160000.1.1

sdbootutil-dracut-measure-pcr-1+git20260506.25d47bf-160000.1.1

sdbootutil-enroll-1+git20260506.25d47bf-160000.1.1

sdbootutil-jeos-firstboot-enroll-1+git20260506.25d47bf-160000.1.1

sdbootutil-kernel-install-1+git20260506.25d47bf-160000.1.1

sdbootutil-snapper-1+git20260506.25d47bf-160000.1.1

sdbootutil-tukit-1+git20260506.25d47bf-160000.1.1

References

* bsc#1243889

* bsc#1247952

* bsc#1252871

* bsc#1253652

* bsc#1254317

* bsc#1254534

* bsc#1254865

* bsc#1256775

* bsc#1257612

* bsc#1258241

* bsc#1258944

References:

* https://www.suse.com/security/cve/CVE-2026-25701.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20878-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here