Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 106 articles for you...
219

Rocky Linux CUPS Moderate Code Execution Threat RLSA-2026-39302

Moderate: cups security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39302", "synopsis": "Moderate: cups security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for cups.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Common UNIX Printing System (CUPS) provides a portable printing layer for Linux, UNIX, and similar operating systems.\n\nSecurity Fix(es):\n\n* cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (CVE-2026-34980)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2454954", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2454954", "description": ""}], "cves": [{"name": "CVE-2026-34980", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34980", "cvss3ScoringVector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L", "cvss3BaseScore": "6.4", "cwe": "CWE-78"}], "references": [], "publishedAt": "2026-07-15T12:06:01.640959Z", "rpms": {"Rocky Linux 10": {"nvras": ["cups-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-lpd-1:2.4.10-18.el10_2.x86_64.rpm", "cups-libs-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-client-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-printerapp-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-ipptool-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-client-1:2.4.10-18.el10_2.x86_64.rpm", "cups-devel-1:2.4.10-18.el10_2.x86_64.rpm", "cups-debugsource-1:2.4.10-18.el10_2.s390x.rpm", "cups-printerapp-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-1:2.4.10-18.el10_2.x86_64.rpm", "cups-lpd-1:2.4.10-18.el10_2.ppc64le.rpm","cups-libs-1:2.4.10-18.el10_2.s390x.rpm", "cups-client-1:2.4.10-18.el10_2.s390x.rpm", "cups-ipptool-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-client-1:2.4.10-18.el10_2.aarch64.rpm", "cups-ipptool-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-client-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-libs-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-lpd-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-1:2.4.10-18.el10_2.src.rpm", "cups-ipptool-1:2.4.10-18.el10_2.s390x.rpm", "cups-filesystem-1:2.4.10-18.el10_2.noarch.rpm", "cups-client-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-debugsource-1:2.4.10-18.el10_2.x86_64.rpm", "cups-printerapp-1:2.4.10-18.el10_2.x86_64.rpm", "cups-debugsource-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-ipptool-1:2.4.10-18.el10_2.aarch64.rpm", "cups-libs-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-libs-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-debugsource-1:2.4.10-18.el10_2.aarch64.rpm", "cups-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-devel-1:2.4.10-18.el10_2.s390x.rpm", "cups-libs-1:2.4.10-18.el10_2.aarch64.rpm", "cups-lpd-1:2.4.10-18.el10_2.s390x.rpm", "cups-lpd-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-client-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-1:2.4.10-18.el10_2.aarch64.rpm", "cups-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-printerapp-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-printerapp-1:2.4.10-18.el10_2.s390x.rpm", "cups-client-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-ipptool-1:2.4.10-18.el10_2.x86_64.rpm", "cups-printerapp-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-printerapp-1:2.4.10-18.el10_2.aarch64.rpm", "cups-devel-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-lpd-1:2.4.10-18.el10_2.aarch64.rpm", "cups-lpd-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-ipptool-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-ipptool-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-1:2.4.10-18.el10_2.s390x.rpm", "cups-lpd-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm","cups-devel-1:2.4.10-18.el10_2.aarch64.rpm", "cups-libs-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-printerapp-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-libs-1:2.4.10-18.el10_2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An important security advisory detailing a moderate CUPS update for Rocky Linux, addressing network access vulnerabilities.. Rocky Linux security update, CUPS security advisory, network vulnerability. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 15, 2026 moderate Rocky Linux
172

Ubuntu 26.04 LTS nghttp2 Important Network Access Vulnerability USN-8495-1

nghttp2 could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8495-1 July 02, 2026 nghttp2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: nghttp2 could allow unintended access to network services. Software Description: - nghttp2: HTTP/2 C Library and tools Details: It was discovered that the nghttp2 nghttpx proxy incorrectly handled HTTP/1.1 Upgrade requests that included a Content-Length header and body. A remote attacker could possibly use this issue to perform HTTP request and response smuggling attacks against backend services. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS nghttp2 1.68.0-2ubuntu0.2 Ubuntu 25.10 nghttp2 1.64.0-1.1ubuntu1.2 Ubuntu 24.04 LTS nghttp2 1.59.0-1ubuntu0.4 Ubuntu 22.04 LTS nghttp2 1.43.0-1ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8495-1 CVE-2026-58055 Package Information: https://launchpad.net/ubuntu/+source/nghttp2/1.68.0-2ubuntu0.2 https://launchpad.net/ubuntu/+source/nghttp2/1.64.0-1.1ubuntu1.2 https://launchpad.net/ubuntu/+source/nghttp2/1.59.0-1ubuntu0.4 https://launchpad.net/ubuntu/+source/nghttp2/1.43.0-1ubuntu0.4 . Unintended access through nghttp2 could expose network services. Update now to secure your Ubuntu system against risks.. nghttp2 security issue, Ubuntu network service access, HTTP/2 library vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 02, 2026 Important Ubuntu
172

Ubuntu Ruby Critical Network Access Issues USN-8478-1 CVE-2026-42246

Ruby could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8478-1 June 29, 2025 ruby2.7, ruby3.0, ruby3.2, ruby3.3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Ruby could allow unintended access to network services. Software Description: - ruby3.3: Object-oriented scripting language - ruby3.2: Object-oriented scripting language - ruby3.0: Object-oriented scripting language - ruby2.7: Object-oriented scripting language Details: It was discovered that Ruby's Net::IMAP library did not properly verify that TLS encryption was started after issuing a STARTTLS command. A remote attacker could use this to perform a machine-in-the-middle attack and silently bypass TLS encryption. (CVE-2026-42246) It was discovered that Ruby's Net::IMAP library did not validate string arguments passed to certain commands. A remote attacker could use this to inject arbitrary IMAP commands. (CVE-2026-42257) It was discovered that Ruby's Net::IMAP library was vulnerable to a denial of service attack when authenticating with SCRAM-SHA1 or SCRAM-SHA256. A hostile server could send a very large iteration count value to cause excessive computation in the client. This issue only affected ruby3.3. (CVE-2026-42256) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libruby3.3 3.3.8-2ubuntu3.1 ruby3.3 3.3.8-2ubuntu3.1 Ubuntu 24.04 LTS libruby3.2 3.2.3-1ubuntu0.24.04.8 ruby3.2 3.2.3-1ubuntu0.24.04.8 Ubuntu 22.04 LTS libruby3.0 3.0.2-7ubuntu2.13 ruby3.0 3.0.2-7ubuntu2.13 Ubuntu 20.04 LTS libruby2.7 2.7.0-5ubuntu1.18+esm5 Available with Ubuntu Pro ruby2.7 2.7.0-5ubuntu1.18+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8478-1 CVE-2026-42246, CVE-2026-42256, CVE-2026-42257 Package Information: https://launchpad.net/ubuntu/+source/ruby3.3/3.3.8-2ubuntu3.1 https://launchpad.net/ubuntu/+source/ruby3.2/3.2.3-1ubuntu0.24.04.8 https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubuntu2.13 . Update your Ubuntu systems to address critical Ruby security issues including unauthorized access and DoS risks.. Ruby security update Ubuntu network services DoS. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important Ubuntu
172

Ubuntu 20.04 18.04 Go Networking Critical Access USN-8416-1

Go Networking could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8416-1 June 09, 2026 golang-golang-x-net-dev vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Go Networking could allow unintended access to network services. Software Description: - golang-golang-x-net-dev: Supplementary Go networking development files Details: It was discovered that Go Networking incorrectly handled certain Punycode-encoded labels in the idna package. An attacker could possibly use this issue to bypass hostname-based access restrictions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS golang-go.net-dev 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3 Available with Ubuntu Pro golang-golang-x-net-dev 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS golang-go.net-dev 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3 Available with Ubuntu Pro golang-golang-x-net-dev 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8416-1 CVE-2026-39821 . Update Ubuntu systems to resolve critical Go Networking issues, preventing unauthorized network access.. Ubuntu Pro, Go Networking, golang-golang-x-net-dev, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 09, 2026 Critical Ubuntu
100

SUSE Linux Enterprise 16 Kernel Important Security Patch 2026-21978-1

An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:21978-1 Release Date: 2026-06-02T07:41:04Z Rating: important References: * bsc#1261630 * bsc#1261845 * bsc#1265384 Cross-References: * CVE-2026-23437 * CVE-2026-31406 * CVE-2026-46333 CVSS scores: * CVE-2026-23437 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23437 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23437 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31406 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31406 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31406 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy (bsc#1261845). * CVE-2026-31406: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() (bsc#1261630). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-862=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_31-default-2-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-debuginfo-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23437.html * https://www.suse.com/security/cve/CVE-2026-31406.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261630 * https://bugzilla.suse.com/show_bug.cgi?id=1261845 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 . Important update for SUSE Linux kernel addressing multiple security issues with recommended installation instructions.. SUSE Linux Kernel Patch Security Update Important. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 03, 2026 Important SuSE
100

SUSE Java-17-OpenJDK Important Security Issues Fixed 2026-1732-1

An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-17-openjdk Announcement ID: SUSE-SU-2026:1732-1 Release Date: 2026-05-07T00:43:53Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.19+10 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integer overflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1732=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-1732=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1732=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1732=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypperin -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1732=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1732=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1732=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1732=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1732=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-src-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-jmods-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * openSUSE Leap 15.4 (noarch) * java-17-openjdk-javadoc-17.0.19.0-150400.3.66.2 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 *java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 *java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html * https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 *https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . Fixes eight security issues and one feature update for java-17-openjdk on SUSE. Critical updates recommended.. java security patch, SUSE update, openjdk vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2026 Important SuSE
100

SUSE 2026 java-11-openjdk Important Security Issues Resolved

An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-11-openjdk Announcement ID: SUSE-SU-2026:1703-1 Release Date: 2026-05-06T08:45:05Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: Upgrade to upstream tag jdk-11.0.31+11 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integeroverflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1703=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1703=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.31.0-3.99.1 * java-11-openjdk-debuginfo-11.0.31.0-3.99.1 * java-11-openjdk-11.0.31.0-3.99.1 * java-11-openjdk-demo-11.0.31.0-3.99.1 * java-11-openjdk-devel-11.0.31.0-3.99.1 * java-11-openjdk-debugsource-11.0.31.0-3.99.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-11-openjdk-headless-11.0.31.0-3.99.1 * java-11-openjdk-debuginfo-11.0.31.0-3.99.1 * java-11-openjdk-11.0.31.0-3.99.1 * java-11-openjdk-demo-11.0.31.0-3.99.1 * java-11-openjdk-devel-11.0.31.0-3.99.1 * java-11-openjdk-debugsource-11.0.31.0-3.99.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html *https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 * https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . Update for java-11-openjdk resolves eight issues and enhances security against unauthorized access on SUSE.. SUSE Security, java-11-openjdk, network vulnerability, update patch, SUSE Linux recommendation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 06, 2026 Important SuSE
202

openSUSE Leap StrongSwan Important Network Access Issues 2026-20547-1

An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for strongswan ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20547-1 Rating: important References: * bsc#1257359 * bsc#1259472 Cross-References: * CVE-2025-9615 * CVE-2026-25075 CVSS scores: * CVE-2025-9615 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-25075 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25075 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for strongswan fixes the following issues: Update to strongswan 6.0.4: - CVE-2025-9615: NetworkManager File Access (bsc#1257359). - CVE-2026-25075: Integer Underflow When Handling EAP-TTLS AVP (bsc#1259472). Changes for strongswan: - Fixed a vulnerability in the NetworkManager plugin that potentially allows using credentials of other local users. This vulnerability has been registered as CVE-2025-9615. - The maximum supported length for section names in swanctl.conf has been increased to the upper limit of 256 characters that's enforced by VICI. - Prevent a crash if a confused peer rekeys a Child SA twice before sending a delete. - Fixed a memory leak if a peer's self-signed certificate is untrusted. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-570=1 Package List: - openSUSE Leap 16.0: strongswan-6.0.4-160000.1.1 strongswan-doc-6.0.4-160000.1.1 strongswan-fips-6.0.4-160000.1.1 strongswan-ipsec-6.0.4-160000.1.1 strongswan-mysql-6.0.4-160000.1.1 strongswan-nm-6.0.4-160000.1.1 strongswan-sqlite-6.0.4-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-9615.html * https://www.suse.com/security/cve/CVE-2026-25075.html . Important security advisory for openSUSE strongswan fixes issues including network access vulnerabilities and integer underflow.. strongswan update, openSUSE advisory, security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 21, 2026 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200