Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for php7 fixes the following issue
* CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL
extension contains a buffer allocation flaw (bsc#1270351).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3165=1
* Legacy Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3165=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3165=1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* php7-sockets-debuginfo-7.4.33-150400.4.63.1
* php7-pdo-7.4.33-150400.4.63.1
* php7-tokenizer-7.4.33-150400.4.63.1
* php7-exif-7.4.33-150400.4.63.1
* php7-pgsql-7.4.33-150400.4.63.1
* php7-embed-debugsource-7.4.33-150400.4.63.1
* php7-posix-debuginfo-7.4.33-150400.4.63.1
* php7-sysvsem-debuginfo-7.4.33-150400.4.63.1
* php7-xmlreader-debuginfo-7.4.33-150400.4.63.1
* php7-mysql-7.4.33-150400.4.63.1
* php7-openssl-debuginfo-7.4.33-150400.4.63.1
* php7-sodium-7.4.33-150400.4.63.1
* php7-embed-7.4.33-150400.4.63.1
* php7-fastcgi-debuginfo-7.4.33-150400.4.63.1
* php7-xsl-7.4.33-150400.4.63.1
* php7-fpm-debugsource-7.4.33-150400.4.63.1
* php7-curl-debuginfo-7.4.33-150400.4.63.1
* php7-zip-debuginfo-7.4.33-150400.4.63.1
* php7-devel-7.4.33-150400.4.63.1
* php7-readline-debuginfo-7.4.33-150400.4.63.1
* php7-sodium-debuginfo-7.4.33-150400.4.63.1
* php7-ftp-debuginfo-7.4.33-150400.4.63.1
* php7-snmp-debuginfo-7.4.33-150400.4.63.1
* php7-tidy-7.4.33-150400.4.63.1
*...
Read the Full Advisory* bsc#1270351
## References:
* https://www.suse.com/security/cve/CVE-2026-14355.html
* https://bugzilla.suse.com/show_bug.cgi?id=1270351
Get the latest Linux and open source security news straight to your inbox.