An update that solves three vulnerabilities can now be installed.. # Security update for mozjs52 Announcement ID: SUSE-SU-2026:1742-1 Release Date: 2026-05-07T07:15:49Z Rating: important References: * bsc#1259713 * bsc#1259728 * bsc#1259731 Cross-References: * CVE-2026-32776 * CVE-2026-32777 * CVE-2026-32778 CVSS scores: * CVE-2026-32776 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32776 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32776 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32776 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32777 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32777 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32777 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32778 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32778 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32778 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32778 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for mozjs52 fixes the following issues * CVE-2026-32776: libexpat: NULL pointer dereference when processing empty external parameter entities inside an entity declaration value (bsc#1259728). * CVE-2026-32777: libexpat: denial of service due to infinite loop in DTD content parsing (bsc#1259713). * CVE-2026-32778:libexpat: NULL pointer dereference in `setContext` on retry after an out-of-memory condition (bsc#1259731). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1742=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * mozjs52-debuginfo-52.6.0-150000.3.12.1 * mozjs52-debugsource-52.6.0-150000.3.12.1 * libmozjs-52-52.6.0-150000.3.12.1 * libmozjs-52-debuginfo-52.6.0-150000.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32776.html * https://www.suse.com/security/cve/CVE-2026-32777.html * https://www.suse.com/security/cve/CVE-2026-32778.html * https://bugzilla.suse.com/show_bug.cgi?id=1259713 * https://bugzilla.suse.com/show_bug.cgi?id=1259728 * https://bugzilla.suse.com/show_bug.cgi?id=1259731 . Three vulnerabilities in mozjs52 fixed by SUSE update ensure better system security and reliability.. SUSE security update, mozjs52 patch, denial of service fix. . Severity: Important. LinuxSecurity.com Team
An update that solves four vulnerabilities can now be installed.. # Security update for mozjs52 Announcement ID: SUSE-SU-2025:4512-1 Release Date: 2025-12-23T12:24:53Z Rating: moderate References: * bsc#1230036 * bsc#1230037 * bsc#1230038 * bsc#1232599 Cross-References: * CVE-2024-45490 * CVE-2024-45491 * CVE-2024-45492 * CVE-2024-50602 CVSS scores: * CVE-2024-45490 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45490 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45490 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45490 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45491 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45491 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2024-45491 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45492 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45492 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45492 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2024-45492 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50602 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-50602 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50602 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for mozjs52 fixes thefollowing issues: * CVE-2024-45491: Fixed integer overflow in dtdCopy (bsc#1230037) * CVE-2024-50602: Fixed DoS via XML_ResumeParser (bsc#1232599) * CVE-2024-45492: Fixed integer overflow in function nextScaffoldPart (bsc#1230038) * CVE-2024-45490: Fixed negative len for XML_ParseBuffer (bsc#1230036) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-4512=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-4512=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * mozjs52-debuginfo-52.6.0-150000.3.9.1 * libmozjs-52-52.6.0-150000.3.9.1 * mozjs52-52.6.0-150000.3.9.1 * libmozjs-52-debuginfo-52.6.0-150000.3.9.1 * mozjs52-debugsource-52.6.0-150000.3.9.1 * mozjs52-devel-52.6.0-150000.3.9.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * mozjs52-debuginfo-52.6.0-150000.3.9.1 * libmozjs-52-52.6.0-150000.3.9.1 * mozjs52-debugsource-52.6.0-150000.3.9.1 * libmozjs-52-debuginfo-52.6.0-150000.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45490.html * https://www.suse.com/security/cve/CVE-2024-45491.html * https://www.suse.com/security/cve/CVE-2024-45492.html * https://www.suse.com/security/cve/CVE-2024-50602.html * https://bugzilla.suse.com/show_bug.cgi?id=1230036 * https://bugzilla.suse.com/show_bug.cgi?id=1230037 * https://bugzilla.suse.com/show_bug.cgi?id=1230038 * https://bugzilla.suse.com/show_bug.cgi?id=1232599 . SUSE update for mozjs52 addresses multiple issues including DoS and integer overflow with a moderate security rating.. SUSE Linux, security update, mozjs52, moderate severity, DoS attack. . LinuxSecurity.com Team
* bsc#1234837 Cross-References: * CVE-2024-56431 . # Security update for mozjs52 Announcement ID: SUSE-SU-2025:1340-1 Release Date: 2025-04-17T11:45:56Z Rating: moderate References: * bsc#1234837 Cross-References: * CVE-2024-56431 CVSS scores: * CVE-2024-56431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-56431 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56431 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for mozjs52 fixes the following issues: * CVE-2024-56431: Fixed a negative shift in huffdec.c (bsc#1234837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-1340=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1340=1 openSUSE-SLE-15.6-2025-1340=1 ## Package List: * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libmozjs-115-0-debuginfo-115.4.0-150600.3.9.1 * mozjs115-devel-115.4.0-150600.3.9.1 * libmozjs-115-0-115.4.0-150600.3.9.1 * mozjs115-debugsource-115.4.0-150600.3.9.1 * mozjs115-debuginfo-115.4.0-150600.3.9.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i686) * libmozjs-115-0-debuginfo-115.4.0-150600.3.9.1 * mozjs115-115.4.0-150600.3.9.1 * mozjs115-devel-115.4.0-150600.3.9.1 * libmozjs-115-0-115.4.0-150600.3.9.1 * mozjs115-debugsource-115.4.0-150600.3.9.1 *mozjs115-debuginfo-115.4.0-150600.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-56431.html * https://bugzilla.suse.com/show_bug.cgi?id=1234837 . Patch for mozjs52 in SUSE addressing a negative shift in huffdec.c, classified as moderate severity, has been implemented.. SUSE Security, mozjs52 Fix, Linux Patch Solution, OpenSUSE Update. . LinuxSecurity.com Team
* bsc#1234837 Cross-References: * CVE-2024-56431 . # Security update for mozjs52 Announcement ID: SUSE-SU-2025:1287-1 Release Date: 2025-04-15T16:25:14Z Rating: moderate References: * bsc#1234837 Cross-References: * CVE-2024-56431 CVSS scores: * CVE-2024-56431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-56431 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56431 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for mozjs52 fixes the following issues: * CVE-2024-56431: Fixed a negative shift in huffdec.c (bsc#1234837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1287=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1287=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * mozjs52-debugsource-52.6.0-150000.3.6.1 * libmozjs-52-debuginfo-52.6.0-150000.3.6.1 * mozjs52-devel-52.6.0-150000.3.6.1 * libmozjs-52-52.6.0-150000.3.6.1 * mozjs52-debuginfo-52.6.0-150000.3.6.1 * mozjs52-52.6.0-150000.3.6.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * libmozjs-52-52.6.0-150000.3.6.1 * mozjs52-debugsource-52.6.0-150000.3.6.1 * mozjs52-debuginfo-52.6.0-150000.3.6.1 * libmozjs-52-debuginfo-52.6.0-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-56431.html *https://bugzilla.suse.com/show_bug.cgi?id=1234837 . SUSE has released a security patch for mozjs52 to fix CVE-2024-56432, labeled with moderate risk for affected systems. Ensure your environment is protected!. security advisory, SUSE Linux, mozjs52, patch instructions, moderate severity. . LinuxSecurity.com Team
* bsc#1234837 Cross-References: * CVE-2024-56431 . # Security update for mozjs52 Announcement ID: SUSE-SU-2025:1288-1 Release Date: 2025-04-15T16:25:36Z Rating: moderate References: * bsc#1234837 Cross-References: * CVE-2024-56431 CVSS scores: * CVE-2024-56431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-56431 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56431 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for mozjs52 fixes the following issues: * CVE-2024-56431: Fixed a negative shift in huffdec.c (bsc#1234837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1288=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1288=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1288=1 ## Package List: * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * libmozjs-78-0-debuginfo-78.15.0-150400.3.14.1 * mozjs78-debuginfo-78.15.0-150400.3.14.1 * libmozjs-78-0-78.15.0-150400.3.14.1 * mozjs78-debugsource-78.15.0-150400.3.14.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i686) * mozjs78-devel-78.15.0-150400.3.14.1 * mozjs78-78.15.0-150400.3.14.1 * libmozjs-78-0-78.15.0-150400.3.14.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.14.1 * mozjs78-debuginfo-78.15.0-150400.3.14.1 *mozjs78-debugsource-78.15.0-150400.3.14.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * mozjs78-devel-78.15.0-150400.3.14.1 * mozjs78-78.15.0-150400.3.14.1 * libmozjs-78-0-78.15.0-150400.3.14.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.14.1 * mozjs78-debuginfo-78.15.0-150400.3.14.1 * mozjs78-debugsource-78.15.0-150400.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2024-56431.html * https://bugzilla.suse.com/show_bug.cgi?id=1234837 . Important security notice for openSUSE users concerning the mrj latest patch addressing vulnerability CVE-2024-56431 impacting mozjs52.. openSUSE Security, mozjs52 Update, SUSE Linux Advisory, Software Patches, Code Execution Risk. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for mozjs52 Announcement ID: SUSE-SU-2025:1288-1 Release Date: 2025-04-15T16:25:36Z Rating: moderate References: * bsc#1234837 Cross-References: * CVE-2024-56431 CVSS scores: * CVE-2024-56431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-56431 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56431 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for mozjs52 fixes the following issues: * CVE-2024-56431: Fixed a negative shift in huffdec.c (bsc#1234837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1288=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1288=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1288=1 ## Package List: * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * libmozjs-78-0-debuginfo-78.15.0-150400.3.14.1 * mozjs78-debuginfo-78.15.0-150400.3.14.1 * libmozjs-78-0-78.15.0-150400.3.14.1 * mozjs78-debugsource-78.15.0-150400.3.14.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i686) * mozjs78-devel-78.15.0-150400.3.14.1 * mozjs78-78.15.0-150400.3.14.1 * libmozjs-78-0-78.15.0-150400.3.14.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.14.1 *mozjs78-debuginfo-78.15.0-150400.3.14.1 * mozjs78-debugsource-78.15.0-150400.3.14.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * mozjs78-devel-78.15.0-150400.3.14.1 * mozjs78-78.15.0-150400.3.14.1 * libmozjs-78-0-78.15.0-150400.3.14.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.14.1 * mozjs78-debuginfo-78.15.0-150400.3.14.1 * mozjs78-debugsource-78.15.0-150400.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2024-56431.html * https://bugzilla.suse.com/show_bug.cgi?id=1234837 . An update for openSUSE resolves a medium severity vulnerability in mozjs52. Patch instructions are now ready for implementation.. openSUSE update, mozjs52 security, SUSE package management, security patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.