An update that solves one vulnerability can now be installed.. # Security update for libxml2 Announcement ID: SUSE-SU-2026:0391-1 Release Date: 2026-02-05T14:23:48Z Rating: low References: * bsc#1256805 Cross-References: * CVE-2026-0989 CVSS scores: * CVE-2026-0989 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0989 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-0989 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issues: * CVE-2026-0989: Fixed call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth when resolving ` ` directives (bsc#1256805) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-391=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-391=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-391=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python311-libxml2-debuginfo-2.10.3-150500.5.35.1 * libxml2-python-debugsource-2.10.3-150500.5.35.1 * libxml2-debugsource-2.10.3-150500.5.35.1 * python3-libxml2-debuginfo-2.10.3-150500.5.35.1 * libxml2-2-2.10.3-150500.5.35.1 * libxml2-tools-2.10.3-150500.5.35.1 * python311-libxml2-2.10.3-150500.5.35.1 * libxml2-tools-debuginfo-2.10.3-150500.5.35.1 * python3-libxml2-2.10.3-150500.5.35.1 * libxml2-2-debuginfo-2.10.3-150500.5.35.1 * libxml2-devel-2.10.3-150500.5.35.1 * openSUSE Leap 15.6 (x86_64) *libxml2-devel-32bit-2.10.3-150500.5.35.1 * libxml2-2-32bit-2.10.3-150500.5.35.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.35.1 * openSUSE Leap 15.6 (noarch) * libxml2-doc-2.10.3-150500.5.35.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.35.1 * libxml2-debugsource-2.10.3-150500.5.35.1 * python3-libxml2-debuginfo-2.10.3-150500.5.35.1 * libxml2-2-2.10.3-150500.5.35.1 * libxml2-tools-2.10.3-150500.5.35.1 * libxml2-tools-debuginfo-2.10.3-150500.5.35.1 * python3-libxml2-2.10.3-150500.5.35.1 * libxml2-2-debuginfo-2.10.3-150500.5.35.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * python311-libxml2-debuginfo-2.10.3-150500.5.35.1 * libxml2-python-debugsource-2.10.3-150500.5.35.1 * libxml2-debugsource-2.10.3-150500.5.35.1 * python3-libxml2-debuginfo-2.10.3-150500.5.35.1 * libxml2-2-2.10.3-150500.5.35.1 * libxml2-tools-2.10.3-150500.5.35.1 * python311-libxml2-2.10.3-150500.5.35.1 * libxml2-tools-debuginfo-2.10.3-150500.5.35.1 * python3-libxml2-2.10.3-150500.5.35.1 * libxml2-2-debuginfo-2.10.3-150500.5.35.1 * libxml2-devel-2.10.3-150500.5.35.1 * openSUSE Leap 15.5 (x86_64) * libxml2-devel-32bit-2.10.3-150500.5.35.1 * libxml2-2-32bit-2.10.3-150500.5.35.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.35.1 * openSUSE Leap 15.5 (noarch) * libxml2-doc-2.10.3-150500.5.35.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libxml2-2-64bit-debuginfo-2.10.3-150500.5.35.1 * libxml2-2-64bit-2.10.3-150500.5.35.1 * libxml2-devel-64bit-2.10.3-150500.5.35.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0989.html * https://bugzilla.suse.com/show_bug.cgi?id=1256805 . Update for libxml2 fixes low severity issue causing potential application crashes due to stack exhaustion.. libxml2 update, openSUSE patch, low severity fix, application security. . Severity: Low. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-5691 https://linux.oracle.com/errata/ELSA-2023-5691.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: bind-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-chroot-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-devel-9.11.4-26.P2.el7_9.15.i686.rpm bind-devel-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-export-devel-9.11.4-26.P2.el7_9.15.i686.rpm bind-export-devel-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-export-libs-9.11.4-26.P2.el7_9.15.i686.rpm bind-export-libs-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-libs-9.11.4-26.P2.el7_9.15.i686.rpm bind-libs-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-libs-lite-9.11.4-26.P2.el7_9.15.i686.rpm bind-libs-lite-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-license-9.11.4-26.P2.el7_9.15.noarch.rpm bind-lite-devel-9.11.4-26.P2.el7_9.15.i686.rpm bind-lite-devel-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-pkcs11-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-pkcs11-devel-9.11.4-26.P2.el7_9.15.i686.rpm bind-pkcs11-devel-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-pkcs11-libs-9.11.4-26.P2.el7_9.15.i686.rpm bind-pkcs11-libs-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-pkcs11-utils-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-sdb-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-sdb-chroot-9.11.4-26.P2.el7_9.15.x86_64.rpm bind-utils-9.11.4-26.P2.el7_9.15.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//bind-9.11.4-26.P2.el7_9.15.src.rpm Related CVEs: CVE-2023-3341 Description of changes: [32:9.11.4-26.P2.15] - Limit the amount of recursion possible in control channel (CVE-2023-3341) _______________________________________________ El-errata mailing list
New bind packages are available for Slackware 15.0, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] bind (SSA:2023-264-01) New bind packages are available for Slackware 15.0, and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/bind-9.16.44-i586-1_slack15.0.txz: Upgraded. This update fixes bugs and a security issue: Limit the amount of recursion that can be performed by isccc_cc_fromwire. For more information, see: https://kb.isc.org/docs/cve-2023-3341 https://www.cve.org/CVERecord?id=CVE-2023-3341 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: eaa6cd04c7f964163ec2d650aa0a51c0 bind-9.16.44-i586-1_slack15.0.txz Slackware x86_64 15.0 package: b7aaa63593db2c829b4380da903bf54e bind-9.16.44-x86_64-1_slack15.0.txz Slackware -current package: 61af61d881473d539452e0df1819cd28 n/bind-9.18.19-i586-1.txz Slackware x86_64 -current package: 59f1a3aaf0a5c38d2d616c5ac7a95ac3 n/bind-9.18.19-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg bind-9.16.44-i586-1_slack15.0.txz Then, restart the name server: # /etc/rc.d/rc.bind restart +-----+ . A fresh bind security patch for Slackware 15.0 tackles significant vulnerabilities and improves overall system reliability through updated packages.. bind security Fix, Slackware 15.0 Security Update, Software Upgrades,Cybersecurity. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2021-3338 https://linux.oracle.com/errata/ELSA-2021-3338.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: hivex-1.3.10-6.12.el7_9.aarch64.rpm perl-hivex-1.3.10-6.12.el7_9.aarch64.rpm hivex-devel-1.3.10-6.12.el7_9.aarch64.rpm ocaml-hivex-1.3.10-6.12.el7_9.aarch64.rpm ocaml-hivex-devel-1.3.10-6.12.el7_9.aarch64.rpm python-hivex-1.3.10-6.12.el7_9.aarch64.rpm ruby-hivex-1.3.10-6.12.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/hivex-1.3.10-6.12.el7_9.src.rpm Related CVEs: CVE-2021-3622 Description of changes: [1.3.10-6.12] - Limit recursion in ri-records (CVE-2021-3622) resolves: rhbz#1976193 _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.