Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 591
Alerts This Week
Warning Icon 1 591

SUSE Afterburn Important Security Update 2026-22917-1 for 13 Threats

suse
Calendar Grey July 27, 2026
Scroller Suse
SUSE issued an important security update for Afterburn addressing 13 vulnerabilities and enhancing system security.
A security update for SUSE Linux Micro 6.0 addresses 13 vulnerabilities in afterburn, enhancing security with fixes for issues related to openssl, regex, and others.

Summary

## This update for afterburn fixes the following issues Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2022-24713: regex: high complexity when parsing regexes with large repetitions on empty sub-expressions can lead to DoS (bsc#1196972). * CVE-2024-12224: idna: privilege escalation due acceptance Punycode labels that do not produce any non-ASCII when decoded (bsc#1243850). * CVE-2025-3416: openssl: use-after-free in `Md::fetch` and `Cipher::fetch` (bsc#1242665). * CVE-2025-5791: users: `root` appended to group listings unless the correct listing has exactly 1024 groups (bsc#1244199). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175).

References

* bsc#1196972

* bsc#1242665

* bsc#1243850

* bsc#1244199

* bsc#1270175

* bsc#1270483

* bsc#1270555

* bsc#1270651

* bsc#1270787

* bsc#1270817

* bsc#1270886

* bsc#1270949

* bsc#1271348

Cross-

* CVE-2022-24713

* CVE-2024-12224

* CVE-2025-3416

* CVE-2025-5791

* CVE-2026-25541

* CVE-2026-41676

* CVE-2026-41677

* CVE-2026-41678

* CVE-2026-41681

* CVE-2026-41898

* CVE-2026-42327

* CVE-2026-44662

* CVE-2026-45784

CVSS scores:

* CVE-2022-24713 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

* CVE-2022-24713 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-12224 ( SUSE ): 2.1

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

* CVE-2024-12224 ( NVD ): 5.1

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22917-1
Release Date: 2026-07-23T11:05:19Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.