Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for aws-nitro-enclaves-cli fixes the following issues
* CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when
returning an oversized length (bsc#1270542).
* CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in
`aes::unwrap_key()` (bsc#1270705).
* CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()`
writing past caller buffer with no length check (bsc#1270747).
* CVE-2026-41898: openssl: information leak to network peers due to unchecked
callback-returned length in PSK and cookie generate trampolines
(bsc#1270839).
* CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders`
when processing certificates with non-UTF-8 OCSP URLs (bsc#1270492).
* CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-
wrap-with-padding (bsc#1270932).
* CVE-2026-45784: openssl: out-of-bounds write in
`CipherCtxRef::cipher_update_inplace` for...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Public Cloud Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3152=1
* Public Cloud Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3152=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3152=1
* Public Cloud Module 15-SP7 (aarch64 x86_64)
* aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-150600.10.12.1
* system-group-ne-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1
* openSUSE Leap 15.6 (aarch64 x86_64)
* aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-150600.10.12.1
* system-group-ne-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1
* Public Cloud Module 15-SP6 (aarch64 x86_64)
*...
Read the Full Advisory* bsc#1270492
* bsc#1270542
* bsc#1270705
* bsc#1270747
* bsc#1270839
* bsc#1270932
* bsc#1270952
## References:
* https://www.suse.com/security/cve/CVE-2026-41677.html
* https://www.suse.com/security/cve/CVE-2026-41678.html
* https://www.suse.com/security/cve/CVE-2026-41681.html
* https://www.suse.com/security/cve/CVE-2026-41898.html
* https://www.suse.com/security/cve/CVE-2026-42327.html
* https://www.suse.com/security/cve/CVE-2026-44662.html
* https://www.suse.com/security/cve/CVE-2026-45784.html
* https://bugzilla.suse.com/show_bug.cgi?id=1270492
* https://bugzilla.suse.com/show_bug.cgi?id=1270542
* https://bugzilla.suse.com/show_bug.cgi?id=1270705
* https://bugzilla.suse.com/show_bug.cgi?id=1270747
* https://bugzilla.suse.com/show_bug.cgi?id=1270839
* https://bugzilla.suse.com/show_bug.cgi?id=1270932
* https://bugzilla.suse.com/show_bug.cgi?id=1270952
Get the latest Linux and open source security news straight to your inbox.