Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for mozjs115 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20769-1 Rating: important References: * bsc#1259713 * bsc#1259728 * bsc#1259731 Cross-References: * CVE-2026-32776 * CVE-2026-32777 * CVE-2026-32778 CVSS scores: * CVE-2026-32776 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32776 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32777 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32777 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32778 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32778 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for mozjs115 fixes the following issues: Changes in mozjs115: - CVE-2026-32776: Fixed a NULL pointer dereference when processing empty external parameter entities inside an entity declaration value (bsc#1259728) - CVE-2026-32777: Fixed a denial of service due to infinite loop in DTD content parsing (bsc#1259713) - CVE-2026-32778: Fixed a NULL pointer dereference in 'setContext' on retry after an out-of-memory condition (bsc#1259731) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-261=1 Package List: - openSUSE Leap 16.0: libmozjs-115-0-115.15.0-bp160.2.1 mozjs115-115.15.0-bp160.2.1 mozjs115-devel-115.15.0-bp160.2.1 References: * https://www.suse.com/security/cve/CVE-2026-32776.html * https://www.suse.com/security/cve/CVE-2026-32777.html * https://www.suse.com/security/cve/CVE-2026-32778.html . Explore the latest openSUSE security advisory for mozjs115 fixing critical issues. Stay protected with the recommended patches.. openSUSE security advisory, mozjs115 update, denial of service fix, NULL pointer security, openSUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for mozjs115 Announcement ID: SUSE-SU-2026:1870-1 Release Date: 2026-05-15T09:19:51Z Rating: important References: * bsc#1259713 * bsc#1259728 * bsc#1259731 Cross-References: * CVE-2026-32776 * CVE-2026-32777 * CVE-2026-32778 CVSS scores: * CVE-2026-32776 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32776 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32776 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32776 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32777 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32777 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32777 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32778 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32778 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32778 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32778 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for mozjs115 fixes the following issues * CVE-2026-32776: libexpat: NULL pointer dereference when processing empty external parameter entities inside anentity declaration value (bsc#1259728). * CVE-2026-32777: libexpat: denial of service due to infinite loop in DTD content parsing (bsc#1259713). * CVE-2026-32778: libexpat: NULL pointer dereference in `setContext` on retry after an out-of-memory condition (bsc#1259731). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1870=1 openSUSE-SLE-15.6-2026-1870=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1870=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1870=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1870=1 ## Package List: * openSUSE Leap 15.6 (i686) * mozjs115-115.4.0-150600.3.12.5 * libmozjs-115-0-115.4.0-150600.3.12.5 * mozjs115-debuginfo-115.4.0-150600.3.12.5 * libmozjs-115-0-debuginfo-115.4.0-150600.3.12.5 * mozjs115-debugsource-115.4.0-150600.3.12.5 * mozjs115-devel-115.4.0-150600.3.12.5 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * mozjs115-115.4.0-150600.3.14.1 * mozjs115-debuginfo-115.4.0-150600.3.14.1 * mozjs115-devel-115.4.0-150600.3.14.1 * libmozjs-115-0-115.4.0-150600.3.14.1 * mozjs115-debugsource-115.4.0-150600.3.14.1 * libmozjs-115-0-debuginfo-115.4.0-150600.3.14.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * mozjs115-debuginfo-115.4.0-150600.3.14.1 * mozjs115-devel-115.4.0-150600.3.14.1 * libmozjs-115-0-115.4.0-150600.3.14.1 * mozjs115-debugsource-115.4.0-150600.3.14.1 * libmozjs-115-0-debuginfo-115.4.0-150600.3.14.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * mozjs115-debuginfo-115.4.0-150600.3.14.1 *mozjs115-devel-115.4.0-150600.3.14.1 * libmozjs-115-0-115.4.0-150600.3.14.1 * mozjs115-debugsource-115.4.0-150600.3.14.1 * libmozjs-115-0-debuginfo-115.4.0-150600.3.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * mozjs115-debuginfo-115.4.0-150600.3.14.1 * mozjs115-devel-115.4.0-150600.3.14.1 * libmozjs-115-0-115.4.0-150600.3.14.1 * mozjs115-debugsource-115.4.0-150600.3.14.1 * libmozjs-115-0-debuginfo-115.4.0-150600.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32776.html * https://www.suse.com/security/cve/CVE-2026-32777.html * https://www.suse.com/security/cve/CVE-2026-32778.html * https://bugzilla.suse.com/show_bug.cgi?id=1259713 * https://bugzilla.suse.com/show_bug.cgi?id=1259728 * https://bugzilla.suse.com/show_bug.cgi?id=1259731 . SUSE's security update addresses three important issues in mozjs115, including denial of service and null pointer vulnerabilities.. SUSE Linux, mozjs115 update, security issues, vulnerablity management. . Severity: Important. LinuxSecurity.com Team
* bsc#1232599 * bsc#1232602 * bsc#1233766 * bsc#1233786 . # Security update for mozjs115 Announcement ID: SUSE-SU-2024:4411-1 Release Date: 2024-12-23T12:46:06Z Rating: moderate References: * bsc#1232599 * bsc#1232602 * bsc#1233766 * bsc#1233786 Cross-References: * CVE-2024-11403 * CVE-2024-11498 * CVE-2024-50602 CVSS scores: * CVE-2024-11403 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2024-11403 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-11498 ( SUSE ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2024-11498 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-50602 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-50602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-50602 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves three vulnerabilities and has one security fix can now be installed. ## Description: This update for mozjs115 fixes the following issues: * CVE-2024-11498: Fixed resource exhaustion via Stack overflow in libjxl (bsc#1233786) * CVE-2024-11403: Fixed out of Bounds Memory Read/Write in libjxl (bsc#1233766) * CVE-2024-50602: Fixed DoS via XML_ResumeParser in libexpat (bsc#1232602) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-4411=1 openSUSE-SLE-15.6-2024-4411=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2024-4411=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i686) * libmozjs-115-0-debuginfo-115.4.0-150600.3.6.1 * libmozjs-115-0-115.4.0-150600.3.6.1 * mozjs115-debuginfo-115.4.0-150600.3.6.1 * mozjs115-debugsource-115.4.0-150600.3.6.1 * mozjs115-devel-115.4.0-150600.3.6.1 * mozjs115-115.4.0-150600.3.6.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libmozjs-115-0-debuginfo-115.4.0-150600.3.6.1 * libmozjs-115-0-115.4.0-150600.3.6.1 * mozjs115-debuginfo-115.4.0-150600.3.6.1 * mozjs115-debugsource-115.4.0-150600.3.6.1 * mozjs115-devel-115.4.0-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11403.html * https://www.suse.com/security/cve/CVE-2024-11498.html * https://www.suse.com/security/cve/CVE-2024-50602.html * https://bugzilla.suse.com/show_bug.cgi?id=1232599 * https://bugzilla.suse.com/show_bug.cgi?id=1232602 * https://bugzilla.suse.com/show_bug.cgi?id=1233766 * https://bugzilla.suse.com/show_bug.cgi?id=1233786 . The latest enhancements to mozjs115 address multiple vulnerabilities, such as Denial of Service risks and memory leaks, significantly improving user security.. mozjs115 security update, SUSE 2024 advisory, moderate risk updates. . LinuxSecurity.com Team
* bsc#1230036 * bsc#1230037 * bsc#1230038 Cross-References: . # Security update for mozjs115 Announcement ID: SUSE-SU-2024:3538-1 Release Date: 2024-10-07T12:16:42Z Rating: moderate References: * bsc#1230036 * bsc#1230037 * bsc#1230038 Cross-References: * CVE-2024-45490 * CVE-2024-45491 * CVE-2024-45492 CVSS scores: * CVE-2024-45490 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45490 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45490 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45491 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45491 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45492 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45492 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45492 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves three vulnerabilities can now be installed. ## Description: This update for mozjs115 fixes the following issues: * CVE-2024-45490: Fixed negative len for XML_ParseBuffer in embedded expat (bnc#1230036) * CVE-2024-45491: Fixed integer overflow in dtdCopy in embedded expat (bnc#1230037) * CVE-2024-45492: Fixed integer overflow in function nextScaffoldPart in embedded expat (bnc#1230038) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2024-3538=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-3538=1 openSUSE-SLE-15.6-2024-3538=1 ## Package List: * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * mozjs115-debugsource-115.4.0-150600.3.3.1 * libmozjs-115-0-115.4.0-150600.3.3.1 * mozjs115-debuginfo-115.4.0-150600.3.3.1 * mozjs115-devel-115.4.0-150600.3.3.1 * libmozjs-115-0-debuginfo-115.4.0-150600.3.3.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i686) * mozjs115-debugsource-115.4.0-150600.3.3.1 * libmozjs-115-0-115.4.0-150600.3.3.1 * mozjs115-debuginfo-115.4.0-150600.3.3.1 * mozjs115-115.4.0-150600.3.3.1 * mozjs115-devel-115.4.0-150600.3.3.1 * libmozjs-115-0-debuginfo-115.4.0-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45490.html * https://www.suse.com/security/cve/CVE-2024-45491.html * https://www.suse.com/security/cve/CVE-2024-45492.html * https://bugzilla.suse.com/show_bug.cgi?id=1230036 * https://bugzilla.suse.com/show_bug.cgi?id=1230037 * https://bugzilla.suse.com/show_bug.cgi?id=1230038 . Essential security enhancements for mozjs115 on SUSE remedying several vulnerabilities with patches now provided.. mozjs115 update, SUSE security, vulnerabilities patching, Linux security, moderate threat updates. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.