Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE Linux Micro 6.0 libsodium Moderate Cryptographic Bypass 2026-20448-1

suse
Calendar Grey February 26, 2026
Dist Suse Esm H88
An update for libsodium fixes cryptographic bypass and validation issues in SUSE Micro 6.0 systems. Apply patches now.
An update that solves two vulnerabilities can now be installed.

Summary

## This update for libsodium fixes the following issues: * CVE-2025-15444: Fixed cryptographic bypass via improper elliptic curve point validation (bsc#1256070). * CVE-2025-69277: Fixed incorrect validation of elliptic curve points in crypto_core_ed25519_is_valid_point function (bsc#1255764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-585=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libsodium-debugsource-1.0.18-5.1 * libsodium23-1.0.18-5.1 * libsodium23-debuginfo-1.0.18-5.1

References

* bsc#1255764

* bsc#1256070

Cross-

* CVE-2025-15444

* CVE-2025-69277

CVSS scores:

* CVE-2025-15444 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

* CVE-2025-15444 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2025-69277 ( SUSE ): 4.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2025-69277 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

* CVE-2025-69277 ( NVD ): 4.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Affected Products:

* SUSE Linux Micro 6.0

An update that solves two vulnerabilities can now be installed.

##

* https://www.suse.com/security/cve/CVE-2025-15444.html

* https://www.suse.com/security/cve/CVE-2025-69277.html

* https://bugzilla.suse.com/show_bug.cgi?id=1255764

Announcement ID: SUSE-SU-2026:20448-1
Release Date: 2026-02-17T08:34:13Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here