Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
A security update for glib2 addresses six vulnerabilities impacting SUSE Linux Enterprise Server 16.0, allowing users to apply safeguards against possible out-of-bounds access and integer overflows.. # Security update for glib2 Announcement ID: SUSE-SU-2026:22846-1 Release Date: 2026-07-22T08:35:52Z Rating: important References: * bsc#1270008 * bsc#1270009 * bsc#1270010 * bsc#1270016 * bsc#1270018 * bsc#1270021 Cross-References: * CVE-2026-58010 * CVE-2026-58011 * CVE-2026-58012 * CVE-2026-58013 * CVE-2026-58014 * CVE-2026-58016 CVSS scores: * CVE-2026-58010 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58012 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58016 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). * CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). * CVE-2026-58012: raw byte regex matches with UTF-8 functions during case- change replacements could cause an out-of- bounds read (bsc#1270016). * CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). * CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). * CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1320=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1320=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * typelib-1_0-GModule-2_0-2.84.4-160000.4.1 * glib2-tools-2.84.4-160000.4.1 * glib2-doc-2.84.4-160000.4.1 * libgio-2_0-0-2.84.4-160000.4.1 * glib2-devel-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-debuginfo-2.84.4-160000.4.1 *glib2-devel-2.84.4-160000.4.1 * glib2-debugsource-2.84.4-160000.4.1 * libgthread-2_0-0-debuginfo-2.84.4-160000.4.1 * libgmodule-2_0-0-debuginfo-2.84.4-160000.4.1 * typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1 * libgirepository-2_0-0-2.84.4-160000.4.1 * libgthread-2_0-0-2.84.4-160000.4.1 * glib2-devel-static-2.84.4-160000.4.1 * libglib-2_0-0-2.84.4-160000.4.1 * libgmodule-2_0-0-2.84.4-160000.4.1 * typelib-1_0-GObject-2_0-2.84.4-160000.4.1 * typelib-1_0-Gio-2_0-2.84.4-160000.4.1 * libgirepository-2_0-0-debuginfo-2.84.4-160000.4.1 * libgio-2_0-0-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-2.84.4-160000.4.1 * libglib-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-tools-debuginfo-2.84.4-160000.4.1 * typelib-1_0-GLib-2_0-2.84.4-160000.4.1 * typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * glib2-lang-2.84.4-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * typelib-1_0-GModule-2_0-2.84.4-160000.4.1 * glib2-tools-2.84.4-160000.4.1 * glib2-doc-2.84.4-160000.4.1 * libgio-2_0-0-2.84.4-160000.4.1 * libgobject-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-devel-debuginfo-2.84.4-160000.4.1 * glib2-devel-2.84.4-160000.4.1 * glib2-debugsource-2.84.4-160000.4.1 * libgthread-2_0-0-debuginfo-2.84.4-160000.4.1 * libgmodule-2_0-0-debuginfo-2.84.4-160000.4.1 * libgirepository-2_0-0-2.84.4-160000.4.1 * libgthread-2_0-0-2.84.4-160000.4.1 * typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1 * glib2-devel-static-2.84.4-160000.4.1 * libglib-2_0-0-2.84.4-160000.4.1 * libgmodule-2_0-0-2.84.4-160000.4.1 * typelib-1_0-GObject-2_0-2.84.4-160000.4.1 * libgirepository-2_0-0-debuginfo-2.84.4-160000.4.1 * typelib-1_0-Gio-2_0-2.84.4-160000.4.1 * libgio-2_0-0-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-2.84.4-160000.4.1 * libglib-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-tools-debuginfo-2.84.4-160000.4.1 *typelib-1_0-GLib-2_0-2.84.4-160000.4.1 * typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * glib2-lang-2.84.4-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58010.html * https://www.suse.com/security/cve/CVE-2026-58011.html * https://www.suse.com/security/cve/CVE-2026-58012.html * https://www.suse.com/security/cve/CVE-2026-58013.html * https://www.suse.com/security/cve/CVE-2026-58014.html * https://www.suse.com/security/cve/CVE-2026-58016.html * https://bugzilla.suse.com/show_bug.cgi?id=1270008 * https://bugzilla.suse.com/show_bug.cgi?id=1270009 * https://bugzilla.suse.com/show_bug.cgi?id=1270010 * https://bugzilla.suse.com/show_bug.cgi?id=1270016 * https://bugzilla.suse.com/show_bug.cgi?id=1270018 * https://bugzilla.suse.com/show_bug.cgi?id=1270021 . A security update for glib2 addresses six issues, including out-of-bounds access exploits impacting SUSE systems.. SUSE update, glib2 security, Linux patch, system vulnerabilities, important update. . Severity: Important. LinuxSecurity.com Team
Update to version 1.7.19. https://github.com/DaveGamble/cJSON/blob/v1.7.19/CHANGELOG.md. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0c3f6c7c67 2026-07-11 01:06:30.201347+00:00 -------------------------------------------------------------------------------- Name : cjson Product : Fedora 44 Version : 1.7.19 Release : 1.fc44 URL : https://github.com/DaveGamble/cJSON Summary : Ultralightweight JSON parser in ANSI C Description : cJSON aims to be the dumbest possible parser that you can get your job done with. It's a single file of C, and a single header file. -------------------------------------------------------------------------------- Update Information: Update to version 1.7.19. https://github.com/DaveGamble/cJSON/blob/v1.7.19/CHANGELOG.md -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 1 2026 Carl George - 1.7.19-1 - Update to version 1.7.19 rhbz#2394084 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2495843 - CVE-2025-57052 cjson: out-of-bounds access in decode_array_index_from_pointer() in cJSON_Utils.c via crafted JSON pointer strings [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2495843 [ 2 ] Bug #2495846 - CVE-2023-26819 cjson: cJSON rejects a valid text [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2495846 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0c3f6c7c67' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
upower 1.91.3: Feature: up-device-battery: Prefer "Standard" over "Fast" charging (!316 (merged), #344 (closed)) Fix: Resolve potential leaks (!327 (merged)) Fix: Potential out-of-bound access (!328 (merged)). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e5305cffc2 2026-07-09 00:54:37.609376+00:00 -------------------------------------------------------------------------------- Name : upower Product : Fedora 44 Version : 1.91.3 Release : 1.fc44 URL : https://upower.freedesktop.org/ Summary : Power Management Service Description : UPower (formerly DeviceKit-power) provides a daemon, API and command line tools for managing power devices attached to the system. -------------------------------------------------------------------------------- Update Information: upower 1.91.3: Feature: up-device-battery: Prefer "Standard" over "Fast" charging (!316 (merged), #344 (closed)) Fix: Resolve potential leaks (!327 (merged)) Fix: Potential out-of-bound access (!328 (merged)) Fix: Improve access control (!326 (merged)) Fix: Remove unused codes (!329 (merged)) Fix: Fix for Asus Battery Charge Threshold Detection (!330 (merged), #347 (closed)) -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 7 2026 Peter Robinson - 1.91.3-1 - Update to 1.91.3 (fixes rhbz#2496407 rhbz#2414589) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2414589 - Settings > Power > Battery Charging: "Preserve Battery Health" can't be set persistently when BIOS Admin Password (a.k.a Setup Password) is set. https://bugzilla.redhat.com/show_bug.cgi?id=2414589 [ 2 ] Bug #2496407 - upower-1.91.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2496407 -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e5305cffc2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves two vulnerabilities can now be installed.. # Security update for glycin-loaders Announcement ID: SUSE-SU-2026:22302-1 Release Date: 2026-06-20T18:27:34Z Rating: moderate References: * bsc#1248035 * bsc#1249010 Cross-References: * CVE-2025-55159 * CVE-2025-58160 CVSS scores: * CVE-2025-55159 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-55159 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-55159 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for glycin-loaders fixes the following issues * CVE-2025-55159: slab: incorrect bounds check in get_disjoint_mut function can lead to undefined behavior or potential crash due to out-of-bounds access (bsc#1248035). * CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249010). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-999=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-999=1 ## PackageList: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * typelib-1_0-GlyGtk4_1-1.2.1-160000.3.1 * libglycin-1-0-1.2.1-160000.3.1 * typelib-1_0-Gly_1-1.2.1-160000.3.1 * glycin-loaders-1.2.1-160000.3.1 * libglycin-gtk4-1-0-1.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * typelib-1_0-GlyGtk4_1-1.2.1-160000.3.1 * libglycin-1-0-1.2.1-160000.3.1 * typelib-1_0-Gly_1-1.2.1-160000.3.1 * glycin-loaders-1.2.1-160000.3.1 * libglycin-gtk4-1-0-1.2.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-55159.html * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1248035 * https://bugzilla.suse.com/show_bug.cgi?id=1249010 . This update addresses two issues in glycin-loaders affecting SUSE Linux Enterprise Server 16.0. Immediate installation is advised.. Glycin Loaders Patch, SUSE Update, Tracing Pollution Fix. . Severity: moderate. LinuxSecurity.com Team
An update that solves 15 vulnerabilities and has 15 bug fixes can now be installed.. openSUSE security update: security update for openssl-3 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21005-1 Rating: important References: * bsc#1259652 * bsc#1266340 * bsc#1266341 * bsc#1266342 * bsc#1266344 * bsc#1266345 * bsc#1266347 * bsc#1266349 * bsc#1266350 * bsc#1266351 * bsc#1266352 * bsc#1266353 * bsc#1266355 * bsc#1266356 * bsc#1266357 Cross-References: * CVE-2026-2673 * CVE-2026-34180 * CVE-2026-34182 * CVE-2026-34183 * CVE-2026-42764 * CVE-2026-42766 * CVE-2026-42767 * CVE-2026-42768 * CVE-2026-42769 * CVE-2026-42770 * CVE-2026-45445 * CVE-2026-45446 * CVE-2026-45447 * CVE-2026-7383 * CVE-2026-9076 CVSS scores: * CVE-2026-2673 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2673 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34180 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34180 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34182 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34182 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34183 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34183 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42764 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42764 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42766 ( SUSE ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42766 ( SUSE ): 6.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( SUSE ): 6CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42768 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N * CVE-2026-42768 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-42769 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42769 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42770 ( SUSE ): 5 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42770 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-45445 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45445 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-45446 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-45447 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45447 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-7383 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7383 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9076 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-9076 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 15 vulnerabilities and has 15 bug fixes can now be installed. Description: This update for openssl-3 fixes the following issues - CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652). - CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). - CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). - CVE-2026-34180: Heap Buffer Over-read in ASN.1Content Parsing (bsc#1266342). - CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). - CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345). - CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347). - CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). - CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). - CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351). - CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352). - CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353). - CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355). - CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1017=1 Package List: - openSUSE Leap 16.0: libopenssl-3-devel-3.5.0-160000.8.1 libopenssl-3-fips-provider-3.5.0-160000.8.1 libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.8.1 libopenssl3-3.5.0-160000.8.1 libopenssl3-x86-64-v3-3.5.0-160000.8.1 openssl-3-3.5.0-160000.8.1 openssl-3-doc-3.5.0-160000.8.1 References: * https://www.suse.com/security/cve/CVE-2026-2673.html * https://www.suse.com/security/cve/CVE-2026-34180.html * https://www.suse.com/security/cve/CVE-2026-34182.html * https://www.suse.com/security/cve/CVE-2026-34183.html * https://www.suse.com/security/cve/CVE-2026-42764.html * https://www.suse.com/security/cve/CVE-2026-42766.html *https://www.suse.com/security/cve/CVE-2026-42767.html * https://www.suse.com/security/cve/CVE-2026-42768.html * https://www.suse.com/security/cve/CVE-2026-42769.html * https://www.suse.com/security/cve/CVE-2026-42770.html * https://www.suse.com/security/cve/CVE-2026-45445.html * https://www.suse.com/security/cve/CVE-2026-45446.html * https://www.suse.com/security/cve/CVE-2026-45447.html * https://www.suse.com/security/cve/CVE-2026-7383.html * https://www.suse.com/security/cve/CVE-2026-9076.html . This critical update resolves 15 vulnerabilities in openssl-3 for openSUSE, including heap and out-of-bounds issues.. openSUSE security advisory, openssl vulnerabilities, important security update. . Severity: Important. LinuxSecurity.com Team
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for mapserver ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20857-1 Rating: important References: * bsc#1260869 * bsc#1266663 Cross-References: * CVE-2026-33721 * CVE-2026-45104 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for mapserver fixes the following issues: Changes in mapserver: - Update to releasee 8.6.3 * SLD parser: fix out of bounds access on SLD with only a Rule with a ElseFilter but without a symbolizer [CVE-2026-33721, boo#1260869] [CVE-2026-45104, boo#1266663] Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-287=1 Package List: - openSUSE Leap 16.0: libjavamapscript-8.6.3-bp160.1.1 libmapserver2-8.6.3-bp160.1.1 mapserver-8.6.3-bp160.1.1 mapserver-devel-8.6.3-bp160.1.1 perl-mapscript-8.6.3-bp160.1.1 php-mapscriptng-8.6.3-bp160.1.1 python313-mapserver-8.6.3-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-33721.html * https://www.suse.com/security/cve/CVE-2026-45104.html . Update for openSUSE Leap 16.0 mapserver addresses critical bugs and security issues requiring immediate attention.. openSUSE mapserver update security vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has 2 bug fixes can now be installed.. openSUSE security update: security update for mesa ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20688-1 Rating: moderate References: * bsc#1261911 * bsc#1261998 Cross-References: * CVE-2026-40393 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has 2 bug fixes can now be installed. Description: This update for Mesa fixes the following issue: - CVE-2026-40393: out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party (bsc#1261998). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-707=1 Package List: - openSUSE Leap 16.0: Mesa-24.3.3-160000.3.1 Mesa-KHR-devel-24.3.3-160000.3.1 Mesa-devel-24.3.3-160000.3.1 Mesa-dri-24.3.3-160000.3.1 Mesa-dri-devel-24.3.3-160000.3.1 Mesa-dri-nouveau-24.3.3-160000.3.1 Mesa-dri-vc4-24.3.3-160000.3.1 Mesa-gallium-24.3.3-160000.3.1 Mesa-libEGL-devel-24.3.3-160000.3.1 Mesa-libEGL1-24.3.3-160000.3.1 Mesa-libGL-devel-24.3.3-160000.3.1 Mesa-libGL1-24.3.3-160000.3.1 Mesa-libGLESv1_CM-devel-24.3.3-160000.3.1 Mesa-libGLESv2-devel-24.3.3-160000.3.1 Mesa-libGLESv3-devel-24.3.3-160000.3.1 Mesa-libOpenCL-24.3.3-160000.3.1 Mesa-libRusticlOpenCL-24.3.3-160000.3.1 Mesa-libd3d-24.3.3-160000.3.1 Mesa-libd3d-devel-24.3.3-160000.3.1 Mesa-libglapi-devel-24.3.3-160000.3.1 Mesa-libglapi0-24.3.3-160000.3.1 Mesa-libva-24.3.3-160000.3.1 Mesa-vulkan-device-select-24.3.3-160000.3.1 Mesa-vulkan-overlay-24.3.3-160000.3.1 libOSMesa-devel-24.3.3-160000.3.1 libOSMesa8-24.3.3-160000.3.1 libgbm-devel-24.3.3-160000.3.1 libgbm1-24.3.3-160000.3.1 libvdpau_d3d12-24.3.3-160000.3.1 libvdpau_nouveau-24.3.3-160000.3.1 libvdpau_r600-24.3.3-160000.3.1 libvdpau_radeonsi-24.3.3-160000.3.1 libvdpau_virtio_gpu-24.3.3-160000.3.1 libvulkan_broadcom-24.3.3-160000.3.1 libvulkan_freedreno-24.3.3-160000.3.1 libvulkan_intel-24.3.3-160000.3.1 libvulkan_lvp-24.3.3-160000.3.1 libvulkan_radeon-24.3.3-160000.3.1 libxatracker-devel-1.0.0-160000.3.1 libxatracker2-1.0.0-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-40393.html . An installation note regarding openSUSE security update addressing moderate issues in Mesa software with critical bug fixes.. openSUSE security patch Mesa vulnerability update. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for Mesa Announcement ID: SUSE-SU-2026:21292-1 Release Date: 2026-04-23T12:57:06Z Rating: moderate References: * bsc#1261998 Cross-References: * CVE-2026-40393 CVSS scores: * CVE-2026-40393 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-40393 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40393 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for Mesa fixes the following issue: * CVE-2026-40393: out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party (bsc#1261998). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-504=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * Mesa-23.3.4-slfo.1.1_3.1 * Mesa-libEGL1-23.3.4-slfo.1.1_3.1 * Mesa-drivers-debugsource-23.3.4-slfo.1.1_3.1 * Mesa-libGL1-debuginfo-23.3.4-slfo.1.1_3.1 * libgbm1-debuginfo-23.3.4-slfo.1.1_3.1 * Mesa-libglapi0-23.3.4-slfo.1.1_3.1 * Mesa-libGL1-23.3.4-slfo.1.1_3.1 * Mesa-dri-debuginfo-23.3.4-slfo.1.1_3.1 * Mesa-debugsource-23.3.4-slfo.1.1_3.1 * Mesa-libEGL1-debuginfo-23.3.4-slfo.1.1_3.1 * libgbm1-23.3.4-slfo.1.1_3.1 * Mesa-libglapi0-debuginfo-23.3.4-slfo.1.1_3.1 * Mesa-dri-23.3.4-slfo.1.1_3.1 * SUSE Linux Micro 6.1 (aarch64 ppc64le x86_64) * Mesa-gallium-debuginfo-23.3.4-slfo.1.1_3.1 * Mesa-gallium-23.3.4-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40393.html * https://bugzilla.suse.com/show_bug.cgi?id=1261998 . SUSEupdates Mesa to address an out-of-bounds access issue with moderate severity. Apply the security patch promptly.. SUSE Linux Micro Mesa Security Moderate Patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.