Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

SUSE 2026 Firebird Critical Security Update Denial Of Service Fixes

suse
Calendar Grey May 15, 2026
Dist Suse Esm H88
Critical update for SUSE Firebird resolves nine security issues including DoS and information leak vulnerabilities.
An update that solves nine vulnerabilities can now be installed.

Summary

## This update for firebird fixes the following issues * CVE-2025-65104: Information leak vulnerability in firebird3 client when used with newer (>= 4) server (bsc#1262330). * CVE-2026-27890: Pre-Auth DOS (bsc#1262328). * CVE-2026-28212: One packet DoS (bsc#1262329). * CVE-2026-28214: Server hangs when using specific clumplet on batch creation (bsc#1262327). * CVE-2026-28224: CryptCallback DOS (bsc#1262326). * CVE-2026-33337: Buffer overflow on parsing corrupted slice packet (bsc#1262325). * CVE-2026-34232: DoS via `op_response` packet from client (bsc#1262324). * CVE-2026-35215: DoS via malicious slice descriptor in slice packet (bsc#1262322). * CVE-2026-40342: Path traversal when declaring external routine (bsc#1262320). ## Patch Instructions:

References

* bsc#1262320

* bsc#1262322

* bsc#1262324

* bsc#1262325

* bsc#1262326

* bsc#1262327

* bsc#1262328

* bsc#1262329

* bsc#1262330

Cross-

* CVE-2025-65104

* CVE-2026-27890

* CVE-2026-28212

* CVE-2026-28214

* CVE-2026-28224

* CVE-2026-33337

* CVE-2026-34232

* CVE-2026-35215

* CVE-2026-40342

CVSS scores:

* CVE-2025-65104 ( SUSE ): 7.1

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L

* CVE-2025-65104 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

* CVE-2025-65104 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

* CVE-2025-65104 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2026-27890 ( SUSE ): 8.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1868-1
Release Date: 2026-05-15T07:50:01Z
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here