Alerts This Week
Warning Icon 1 1,149
Alerts This Week
Warning Icon 1 1,149

SUSE Linux Micro 6.0 6.2 polkit Moderate Memory Exhaustion DoS Risk

suse
Calendar Grey April 8, 2026
Dist Suse Esm H88
Update resolves four issues in polkit impacting SUSE Linux Micro 6.0 & 6.2, requiring immediate patch installation.
An update that solves four vulnerabilities can now be installed.

Summary

### This update for polkit fixes the following issue: * CVE-2026-4897: Fixed possible OOM condition via specially crafted input to `polkit-agent-helper-1` (bsc#1260859). ## Security update for expat ### This update for expat fixes the following issues: * CVE-2026-32776: NULL pointer dereference when processing empty external parameter entities inside an entity declaration value (bsc#1259726). * CVE-2026-32777: denial of service due to infinite loop in DTD content parsing (bsc#1259711). * CVE-2026-32778: NULL pointer dereference in `setContext` on retry after an out-of-memory condition (bsc#1259729). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

* bsc#1259711

* bsc#1259726

* bsc#1259729

* bsc#1260859

Cross-

* CVE-2026-32776

* CVE-2026-32777

* CVE-2026-32778

* CVE-2026-4897

CVSS scores:

* CVE-2026-32776 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-32776 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-32776 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2026-32776 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-32777 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-32777 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-32777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Announcement ID: SUSE-SU-2026:20969-1
Release Date: 2026-04-07T11:49:24Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here