Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE OVMF Important DoS Vulnerabilities Announced 2026-1952-1

suse
Calendar Grey May 18, 2026
Dist Suse Esm H88
SUSE update addresses four important vulnerabilities in ovmf. See CVE details and install instructions for Users.
An update that solves four vulnerabilities can now be installed.

Summary

## This update for ovmf fixes the following issues * CVE-2026-25833: mbedtls: buffer underflow in x509_inet_pton_ipv6() (bsc#1261476). * CVE-2026-25834: mbedtls: Algorithm downgrade vulnerability (bsc#1261477). * CVE-2026-25835: mbedtls: PSA random generator cloning (bsc#1261478). * CVE-2026-34874: mbedtls: NULL pointer dereference when setting a distinguished name (bsc#1261469). Changes for ovmf: * Update mbedtls to 3.6.6. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1952=1 * Server Applications Module 15-SP7

References

* bsc#1261469

* bsc#1261476

* bsc#1261477

* bsc#1261478

Cross-

* CVE-2026-25833

* CVE-2026-25834

* CVE-2026-25835

* CVE-2026-34874

CVSS scores:

* CVE-2026-25833 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-25833 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-25833 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-25834 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2026-25834 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

* CVE-2026-25834 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

* CVE-2026-25835 ( SUSE ): 8.5

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1952-1
Release Date: 2026-05-18T07:52:56Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here