## This update for firebird fixes the following issues * CVE-2025-65104: Information leak vulnerability in firebird3 client when used with newer (>= 4) server (bsc#1262330). * CVE-2026-27890: Pre-Auth DOS (bsc#1262328). * CVE-2026-28212: One packet DoS (bsc#1262329). * CVE-2026-28214: Server hangs when using specific clumplet on batch creation (bsc#1262327). * CVE-2026-28224: CryptCallback DOS (bsc#1262326). * CVE-2026-33337: Buffer overflow on parsing corrupted slice packet (bsc#1262325). * CVE-2026-34232: DoS via `op_response` packet from client (bsc#1262324). * CVE-2026-35215: DoS via malicious slice descriptor in slice packet (bsc#1262322). * CVE-2026-40342: Path traversal when declaring external routine (bsc#1262320). ## Patch Instructions:
* bsc#1262320
* bsc#1262322
* bsc#1262324
* bsc#1262325
* bsc#1262326
* bsc#1262327
* bsc#1262328
* bsc#1262329
* bsc#1262330
Cross-
* CVE-2025-65104
* CVE-2026-27890
* CVE-2026-28212
* CVE-2026-28214
* CVE-2026-28224
* CVE-2026-33337
* CVE-2026-34232
* CVE-2026-35215
* CVE-2026-40342
CVSS scores:
* CVE-2025-65104 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L
* CVE-2025-65104 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
* CVE-2025-65104 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
* CVE-2025-65104 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-27890 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Get the latest Linux and open source security news straight to your inbox.