Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

openSUSE aws-nitro-enclaves-cli Important Multiple Risks Fix 2026-21406-1

opensuse
Calendar Grey July 24, 2026
Scroller Opensuse
Address 7 issues in aws-nitro-enclaves-cli with important updates for openSUSE. Stay secure and update promptly.
openSUSE released a security update for aws-nitro-enclaves-cli, addressing seven vulnerabilities, including buffer overflows and arbitrary code execution, alongside bug fixes and a...

Description

This update for aws-nitro-enclaves-cli fixes the following issues:

- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-

openssl crate (bsc#1270542).

- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270705).

- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate

(bsc#1270747).

- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent

memory in rust-openssl crate (bsc#1270839).

- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate

(bsc#1270492).

- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate

(bsc#1270932).

- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-160000.1.1

aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-160000.1.1

system-group-ne-1.4.5~git0.18a5f6f-160000.1.1

References

* bsc#1270492

* bsc#1270542

* bsc#1270705

* bsc#1270747

* bsc#1270839

* bsc#1270932

* bsc#1270952

References:

* https://www.suse.com/security/cve/CVE-2026-41677.html

* https://www.suse.com/security/cve/CVE-2026-41678.html

* https://www.suse.com/security/cve/CVE-2026-41681.html

* https://www.suse.com/security/cve/CVE-2026-41898.html

* https://www.suse.com/security/cve/CVE-2026-42327.html

* https://www.suse.com/security/cve/CVE-2026-44662.html

* https://www.suse.com/security/cve/CVE-2026-45784.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21406-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.