Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 553
Alerts This Week
Warning Icon 1 553

SUSE Afterburn Key Security Update 2026-22827-1 for CVE-2026-25541

suse
Calendar Grey July 27, 2026
Scroller Suse
SUSE security update addresses nine vulnerabilities in afterburn software, enhancing system protection and stability.
SUSE released an important security update for afterburn, addressing nine vulnerabilities related to OpenSSL and other components, with instructions for installation on affected se...

Summary

## This update for afterburn fixes the following issues: Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817).

References

* bsc#1270175

* bsc#1270483

* bsc#1270555

* bsc#1270651

* bsc#1270787

* bsc#1270817

* bsc#1270886

* bsc#1270949

* bsc#1271348

Cross-

* CVE-2026-25541

* CVE-2026-41676

* CVE-2026-41677

* CVE-2026-41678

* CVE-2026-41681

* CVE-2026-41898

* CVE-2026-42327

* CVE-2026-44662

* CVE-2026-45784

CVSS scores:

* CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-25541 ( NVD ): 5.5

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-41676 ( SUSE ): 8.3

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22827-1
Release Date: 2026-07-20T09:31:31Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.