Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-22528 http://linux.oracle.com/errata/ELSA-2026-22528.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: mod_http2-2.0.29-4.el10_2.2.x86_64.rpm aarch64: mod_http2-2.0.29-4.el10_2.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/mod_http2-2.0.29-4.el10_2.2.src.rpm Related CVEs: CVE-2025-53020 Description of changes: [2.0.29-4.2] - Resolves: RHEL-188008 - address CVE-2026-43951, CVE-2026-48913 [2.0.29-4.1] - Resolves: RHEL-182410 - mod_http2: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975) [2.0.29-4] - Resolves: RHEL-166269 - httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020) _______________________________________________ El-errata mailing list
An update that solves 429 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for chromium ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20916-1 Rating: critical References: * bsc#1265854 * bsc#1267706 Cross-References: * CVE-2026-10881 * CVE-2026-10882 * CVE-2026-10883 * CVE-2026-10884 * CVE-2026-10885 * CVE-2026-10886 * CVE-2026-10887 * CVE-2026-10888 * CVE-2026-10889 * CVE-2026-10890 * CVE-2026-10891 * CVE-2026-10892 * CVE-2026-10893 * CVE-2026-10894 * CVE-2026-10895 * CVE-2026-10896 * CVE-2026-10897 * CVE-2026-10898 * CVE-2026-10899 * CVE-2026-10900 * CVE-2026-10901 * CVE-2026-10902 * CVE-2026-10903 * CVE-2026-10904 * CVE-2026-10905 * CVE-2026-10906 * CVE-2026-10907 * CVE-2026-10908 * CVE-2026-10909 * CVE-2026-10910 * CVE-2026-10911 * CVE-2026-10912 * CVE-2026-10913 * CVE-2026-10914 * CVE-2026-10915 * CVE-2026-10916 * CVE-2026-10917 * CVE-2026-10918 * CVE-2026-10919 * CVE-2026-10920 * CVE-2026-10921 * CVE-2026-10922 * CVE-2026-10923 * CVE-2026-10924 * CVE-2026-10925 * CVE-2026-10926 * CVE-2026-10927 * CVE-2026-10928 * CVE-2026-10929 * CVE-2026-10930 * CVE-2026-10931 * CVE-2026-10932 * CVE-2026-10933 * CVE-2026-10934 * CVE-2026-10935 * CVE-2026-10936 * CVE-2026-10937 * CVE-2026-10938 * CVE-2026-10939 * CVE-2026-10940 * CVE-2026-10941 * CVE-2026-10942 * CVE-2026-10943 * CVE-2026-10944 * CVE-2026-10945 * CVE-2026-10946 * CVE-2026-10947 * CVE-2026-10948 * CVE-2026-10949 * CVE-2026-10950 * CVE-2026-10951 * CVE-2026-10952 * CVE-2026-10953 * CVE-2026-10954 * CVE-2026-10955 * CVE-2026-10956 * CVE-2026-10957 * CVE-2026-10958 * CVE-2026-10959 * CVE-2026-10960 * CVE-2026-10961 * CVE-2026-10962 * CVE-2026-10963 * CVE-2026-10964 * CVE-2026-10965 * CVE-2026-10966 * CVE-2026-10967 * CVE-2026-10968 * CVE-2026-10969 * CVE-2026-10970 *CVE-2026-10971 * CVE-2026-10972 * CVE-2026-10973 * CVE-2026-10974 * CVE-2026-10975 * CVE-2026-10976 * CVE-2026-10977 * CVE-2026-10978 * CVE-2026-10979 * CVE-2026-10980 * CVE-2026-10981 * CVE-2026-10982 * CVE-2026-10983 * CVE-2026-10984 * CVE-2026-10985 * CVE-2026-10986 * CVE-2026-10987 * CVE-2026-10988 * CVE-2026-10989 * CVE-2026-10990 * CVE-2026-10991 * CVE-2026-10992 * CVE-2026-10993 * CVE-2026-10994 * CVE-2026-10995 * CVE-2026-10996 * CVE-2026-10997 * CVE-2026-10998 * CVE-2026-10999 * CVE-2026-11000 * CVE-2026-11001 * CVE-2026-11002 * CVE-2026-11003 * CVE-2026-11004 * CVE-2026-11005 * CVE-2026-11006 * CVE-2026-11007 * CVE-2026-11008 * CVE-2026-11009 * CVE-2026-11010 * CVE-2026-11011 * CVE-2026-11012 * CVE-2026-11013 * CVE-2026-11014 * CVE-2026-11015 * CVE-2026-11016 * CVE-2026-11017 * CVE-2026-11018 * CVE-2026-11019 * CVE-2026-11020 * CVE-2026-11021 * CVE-2026-11022 * CVE-2026-11023 * CVE-2026-11024 * CVE-2026-11025 * CVE-2026-11026 * CVE-2026-11027 * CVE-2026-11028 * CVE-2026-11029 * CVE-2026-11030 * CVE-2026-11031 * CVE-2026-11032 * CVE-2026-11033 * CVE-2026-11034 * CVE-2026-11035 * CVE-2026-11036 * CVE-2026-11037 * CVE-2026-11038 * CVE-2026-11039 * CVE-2026-11040 * CVE-2026-11041 * CVE-2026-11042 * CVE-2026-11043 * CVE-2026-11044 * CVE-2026-11045 * CVE-2026-11046 * CVE-2026-11047 * CVE-2026-11048 * CVE-2026-11049 * CVE-2026-11050 * CVE-2026-11051 * CVE-2026-11052 * CVE-2026-11053 * CVE-2026-11054 * CVE-2026-11055 * CVE-2026-11056 * CVE-2026-11057 * CVE-2026-11058 * CVE-2026-11059 * CVE-2026-11060 * CVE-2026-11061 * CVE-2026-11062 * CVE-2026-11063 * CVE-2026-11064 * CVE-2026-11065 * CVE-2026-11066 * CVE-2026-11067 * CVE-2026-11068 * CVE-2026-11069 * CVE-2026-11070 * CVE-2026-11071 * CVE-2026-11072 * CVE-2026-11073 * CVE-2026-11074 * CVE-2026-11075 * CVE-2026-11076 * CVE-2026-11077 *CVE-2026-11078 * CVE-2026-11079 * CVE-2026-11080 * CVE-2026-11081 * CVE-2026-11082 * CVE-2026-11083 * CVE-2026-11084 * CVE-2026-11085 * CVE-2026-11086 * CVE-2026-11087 * CVE-2026-11088 * CVE-2026-11089 * CVE-2026-11090 * CVE-2026-11091 * CVE-2026-11092 * CVE-2026-11093 * CVE-2026-11094 * CVE-2026-11095 * CVE-2026-11096 * CVE-2026-11097 * CVE-2026-11098 * CVE-2026-11099 * CVE-2026-11100 * CVE-2026-11101 * CVE-2026-11102 * CVE-2026-11103 * CVE-2026-11104 * CVE-2026-11105 * CVE-2026-11106 * CVE-2026-11107 * CVE-2026-11108 * CVE-2026-11109 * CVE-2026-11110 * CVE-2026-11111 * CVE-2026-11112 * CVE-2026-11113 * CVE-2026-11114 * CVE-2026-11115 * CVE-2026-11116 * CVE-2026-11117 * CVE-2026-11118 * CVE-2026-11119 * CVE-2026-11120 * CVE-2026-11121 * CVE-2026-11122 * CVE-2026-11123 * CVE-2026-11124 * CVE-2026-11125 * CVE-2026-11126 * CVE-2026-11127 * CVE-2026-11128 * CVE-2026-11129 * CVE-2026-11130 * CVE-2026-11131 * CVE-2026-11132 * CVE-2026-11133 * CVE-2026-11134 * CVE-2026-11135 * CVE-2026-11136 * CVE-2026-11137 * CVE-2026-11138 * CVE-2026-11139 * CVE-2026-11140 * CVE-2026-11141 * CVE-2026-11142 * CVE-2026-11143 * CVE-2026-11144 * CVE-2026-11145 * CVE-2026-11146 * CVE-2026-11147 * CVE-2026-11148 * CVE-2026-11149 * CVE-2026-11150 * CVE-2026-11151 * CVE-2026-11152 * CVE-2026-11153 * CVE-2026-11154 * CVE-2026-11155 * CVE-2026-11156 * CVE-2026-11157 * CVE-2026-11158 * CVE-2026-11159 * CVE-2026-11160 * CVE-2026-11161 * CVE-2026-11162 * CVE-2026-11163 * CVE-2026-11164 * CVE-2026-11165 * CVE-2026-11166 * CVE-2026-11167 * CVE-2026-11168 * CVE-2026-11169 * CVE-2026-11170 * CVE-2026-11171 * CVE-2026-11172 * CVE-2026-11173 * CVE-2026-11174 * CVE-2026-11175 * CVE-2026-11176 * CVE-2026-11177 * CVE-2026-11178 * CVE-2026-11179 * CVE-2026-11180 * CVE-2026-11181 * CVE-2026-11182 * CVE-2026-11183 * CVE-2026-11184 *CVE-2026-11185 * CVE-2026-11186 * CVE-2026-11187 * CVE-2026-11188 * CVE-2026-11189 * CVE-2026-11190 * CVE-2026-11191 * CVE-2026-11192 * CVE-2026-11193 * CVE-2026-11194 * CVE-2026-11195 * CVE-2026-11196 * CVE-2026-11197 * CVE-2026-11198 * CVE-2026-11199 * CVE-2026-11200 * CVE-2026-11201 * CVE-2026-11202 * CVE-2026-11203 * CVE-2026-11204 * CVE-2026-11205 * CVE-2026-11206 * CVE-2026-11207 * CVE-2026-11208 * CVE-2026-11209 * CVE-2026-11210 * CVE-2026-11211 * CVE-2026-11212 * CVE-2026-11213 * CVE-2026-11214 * CVE-2026-11215 * CVE-2026-11216 * CVE-2026-11217 * CVE-2026-11218 * CVE-2026-11219 * CVE-2026-11220 * CVE-2026-11221 * CVE-2026-11222 * CVE-2026-11223 * CVE-2026-11224 * CVE-2026-11225 * CVE-2026-11226 * CVE-2026-11227 * CVE-2026-11228 * CVE-2026-11229 * CVE-2026-11230 * CVE-2026-11231 * CVE-2026-11232 * CVE-2026-11233 * CVE-2026-11234 * CVE-2026-11235 * CVE-2026-11236 * CVE-2026-11237 * CVE-2026-11238 * CVE-2026-11239 * CVE-2026-11240 * CVE-2026-11241 * CVE-2026-11242 * CVE-2026-11243 * CVE-2026-11244 * CVE-2026-11245 * CVE-2026-11246 * CVE-2026-11247 * CVE-2026-11248 * CVE-2026-11249 * CVE-2026-11250 * CVE-2026-11251 * CVE-2026-11252 * CVE-2026-11253 * CVE-2026-11254 * CVE-2026-11255 * CVE-2026-11256 * CVE-2026-11257 * CVE-2026-11258 * CVE-2026-11259 * CVE-2026-11260 * CVE-2026-11261 * CVE-2026-11262 * CVE-2026-11263 * CVE-2026-11264 * CVE-2026-11265 * CVE-2026-11266 * CVE-2026-11267 * CVE-2026-11268 * CVE-2026-11269 * CVE-2026-11270 * CVE-2026-11271 * CVE-2026-11272 * CVE-2026-11273 * CVE-2026-11274 * CVE-2026-11275 * CVE-2026-11276 * CVE-2026-11277 * CVE-2026-11278 * CVE-2026-11279 * CVE-2026-11280 * CVE-2026-11281 * CVE-2026-11282 * CVE-2026-11283 * CVE-2026-11284 * CVE-2026-11285 * CVE-2026-11286 * CVE-2026-11287 * CVE-2026-11288 * CVE-2026-11289 * CVE-2026-11290 * CVE-2026-11291 *CVE-2026-11292 * CVE-2026-11293 * CVE-2026-11294 * CVE-2026-11295 * CVE-2026-11296 * CVE-2026-11297 * CVE-2026-11298 * CVE-2026-11299 * CVE-2026-11300 * CVE-2026-11301 * CVE-2026-11302 * CVE-2026-11303 * CVE-2026-11304 * CVE-2026-11305 * CVE-2026-11306 * CVE-2026-11307 * CVE-2026-11308 * CVE-2026-11309 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 429 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for chromium fixes the following issues: Changes in chromium: - Chromium 149 (149.0.7827.53) stable (boo#1267706): * CVE-2026-10881: Out of bounds read and write in ANGLE * CVE-2026-10882: Use after free in Network * CVE-2026-10883: Out of bounds write in ANGLE * CVE-2026-10884: Use after free in Chromecast * CVE-2026-10885: Use after free in Chrome for iOS * CVE-2026-10886: Use after free in FileSystem * CVE-2026-10887: Use after free in Chromoting * CVE-2026-10888: Use after free in Cast Streaming * CVE-2026-10889: Out of bounds read in ANGLE * CVE-2026-10890: Use after free in Cast * CVE-2026-10891: Use after free in GFX * CVE-2026-10892: Out of bounds write in GPU * CVE-2026-10893: Use after free in Chromoting * CVE-2026-10894: Use after free in Printing * CVE-2026-10895: Use after free in Ozone * CVE-2026-10896: Use after free in Chrome for iOS * CVE-2026-10897: Out of bounds write in GPU * CVE-2026-10898: Stack buffer overflow in GPU * CVE-2026-10899: Use after free in Ozone * CVE-2026-10900: Use after free in Passwords * CVE-2026-10901: Use after free in Passwords * CVE-2026-10902: Use after free in Ozone * CVE-2026-10903: Use after free in WebRTC * CVE-2026-10904: Inappropriate implementation in V8 * CVE-2026-10905: Use after free in Network * CVE-2026-10906: Use after free in WebAuthentication * CVE-2026-10907: Out of bounds write in ANGLE * CVE-2026-10908: Use after free in FullScreen *CVE-2026-10909: Use after free in Dawn * CVE-2026-10910: Type Confusion in V8 * CVE-2026-10911: Insufficient validation of untrusted input in Media * CVE-2026-10912: Insufficient validation of untrusted input in Extensions * CVE-2026-10913: Use after free in ANGLE * CVE-2026-10914: Use after free in ANGLE * CVE-2026-10915: Use after free in Core * CVE-2026-10916: Insufficient validation of untrusted input in DevTools * CVE-2026-10917: Insufficient validation of untrusted input in Media * CVE-2026-10918: Use after free in Viz * CVE-2026-10919: Use after free in ANGLE * CVE-2026-10920: Insufficient validation of untrusted input in WebShare * CVE-2026-10921: Integer overflow in Dawn * CVE-2026-10922: Insufficient validation of untrusted input in DevTools * CVE-2026-10923: Use after free in WebAppInstalls * CVE-2026-10924: Integer overflow in Chromecast * CVE-2026-10925: Out of bounds write in Skia * CVE-2026-10926: Use after free in Cast * CVE-2026-10927: Out of bounds read in Dawn * CVE-2026-10928: Script injection in Headless * CVE-2026-10929: Heap buffer overflow in ANGLE * CVE-2026-10930: Out of bounds read in ANGLE * CVE-2026-10931: Use after free in FileSystem * CVE-2026-10932: Use after free in UI * CVE-2026-10933: Use after free in Audio * CVE-2026-10934: Use after free in Autofill * CVE-2026-10935: Inappropriate implementation in V8 * CVE-2026-10936: Type Confusion in V8 * CVE-2026-10937: Inappropriate implementation in Passwords * CVE-2026-10938: Insufficient validation of untrusted input in Input * CVE-2026-10939: Use after free in WebRTC * CVE-2026-10940: Race in Codecs * CVE-2026-10941: Out of bounds memory access in Skia * CVE-2026-10942: Insufficient validation of untrusted input in UI * CVE-2026-10943: Use after free in WebRTC * CVE-2026-10944: Insufficient policy enforcement in Autofill * CVE-2026-10945: Use after free in PDF * CVE-2026-10946: Heap buffer overflow in Media * CVE-2026-10947: Use after free in WebRTC *CVE-2026-10948: Use after free in WebRTC * CVE-2026-10949: Heap buffer overflow in Video * CVE-2026-10950: Insufficient policy enforcement in Autofill * CVE-2026-10951: Use after free in Autofill * CVE-2026-10952: Use after free in Chrome for iOS * CVE-2026-10953: Use after free in Core * CVE-2026-10954: Use after free in Actor * CVE-2026-10955: Type Confusion in ANGLE * CVE-2026-10956: Use after free in MimeHandlerView * CVE-2026-10957: Use after free in Glic * CVE-2026-10958: Use after free in Chrome for iOS * CVE-2026-10959: Use after free in Input * CVE-2026-10960: Uninitialized Use in Codecs * CVE-2026-10961: Use after free in Chrome for iOS * CVE-2026-10962: Type Confusion in Media * CVE-2026-10963: Integer overflow in V8 * CVE-2026-10964: Integer overflow in V8 * CVE-2026-10965: Integer overflow in DevTools * CVE-2026-10966: Insufficient validation of untrusted input in Codecs * CVE-2026-10967: Use after free in SurfaceCapture * CVE-2026-10968: Insufficient validation of untrusted input in Dawn * CVE-2026-10969: Insufficient validation of untrusted input in Extensions * CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups * CVE-2026-10971: Insufficient validation of untrusted input in Printing * CVE-2026-10972: Use after free in Ozone * CVE-2026-10973: Uninitialized Use in Dawn * CVE-2026-10974: Insufficient validation of untrusted input in ANGLE * CVE-2026-10975: Use after free in WebRTC * CVE-2026-10976: Uninitialized Use in Dawn * CVE-2026-10977: Uninitialized Use in Skia * CVE-2026-10978: Use after free in Chromoting * CVE-2026-10979: Out of bounds read in ANGLE * CVE-2026-10980: Insufficient validation of untrusted input in DevTools * CVE-2026-10981: Insufficient validation of untrusted input in Codecs * CVE-2026-10982: Use after free in WebXR * CVE-2026-10983: Insufficient validation of untrusted input in Dawn * CVE-2026-10984: Inappropriate implementation in Accessibility * CVE-2026-10985: Out ofbounds read in Skia * CVE-2026-10986: Integer overflow in Media * CVE-2026-10987: Integer overflow in V8 * CVE-2026-10988: Use after free in Views * CVE-2026-10989: Inappropriate implementation in V8 * CVE-2026-10990: Use after free in Glic * CVE-2026-10991: Use after free in V8 * CVE-2026-10992: Insufficient data validation in Animation * CVE-2026-10993: Heap buffer overflow in Skia * CVE-2026-10994: Uninitialized Use in ANGLE * CVE-2026-10995: Heap buffer overflow in TabStrip * CVE-2026-10996: Inappropriate implementation in Workers * CVE-2026-10997: Insufficient policy enforcement in Extensions * CVE-2026-10998: Out of bounds read in Media * CVE-2026-10999: Out of bounds memory access in ANGLE * CVE-2026-11000: Use after free in Fonts * CVE-2026-11001: Incorrect security UI in Payments * CVE-2026-11002: Use after free in Autofill * CVE-2026-11003: Use after free in WebRTC * CVE-2026-11004: Out of bounds read in ANGLE * CVE-2026-11005: Out of bounds read in ANGLE * CVE-2026-11006: Out of bounds read in Dawn * CVE-2026-11007: Insufficient validation of untrusted input in WebView * CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11009: Use after free in USB * CVE-2026-11010: Use after free in WebShare * CVE-2026-11011: Insufficient policy enforcement in Password Manager * CVE-2026-11012: Use after free in Serial * CVE-2026-11013: Insufficient validation of untrusted input in Network * CVE-2026-11014: Insufficient policy enforcement in Extensions * CVE-2026-11015: Out of bounds read in WebGPU * CVE-2026-11016: Insufficient validation of untrusted input in Network * CVE-2026-11017: Inappropriate implementation in Link Preview * CVE-2026-11018: Insufficient policy enforcement in Actor * CVE-2026-11019: Inappropriate implementation in Payments * CVE-2026-11020: Inappropriate implementation in Extensions * CVE-2026-11021: Insufficient validation of untrusted input in GPU * CVE-2026-11022: Insufficientvalidation of untrusted input in DevTools * CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11024: Stack buffer overflow in Skia * CVE-2026-11025: Insufficient policy enforcement in Navigation * CVE-2026-11026: Insufficient policy enforcement in Extensions * CVE-2026-11027: Insufficient validation of untrusted input in Glic * CVE-2026-11028: Use after free in Media * CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop * CVE-2026-11030: Use after free in Network * CVE-2026-11031: Insufficient validation of untrusted input in Password Manager * CVE-2026-11032: Insufficient data validation in Password Manager * CVE-2026-11033: Uninitialized Use in WebML * CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync * CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs * CVE-2026-11036: Inappropriate implementation in DOM * CVE-2026-11037: Out of bounds write in Codecs * CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity * CVE-2026-11039: Uninitialized Use in Skia * CVE-2026-11040: Use after free in ANGLE * CVE-2026-11041: Insufficient validation of untrusted input in Media * CVE-2026-11042: Use after free in Views * CVE-2026-11043: Out of bounds write in ANGLE * CVE-2026-11044: Integer overflow in ANGLE * CVE-2026-11045: Insufficient validation of untrusted input in GPU * CVE-2026-11046: Insufficient validation of untrusted input in Media * CVE-2026-11047: Insufficient validation of untrusted input in Base * CVE-2026-11048: Inappropriate implementation in Extensions * CVE-2026-11049: Use after free in Password Manager * CVE-2026-11050: Use after free in V8 * CVE-2026-11051: Out of bounds read in ANGLE * CVE-2026-11052: Type Confusion in GPU * CVE-2026-11053: VULNERABILITY in WebRTC * CVE-2026-11054: Use after free in WebRTC * CVE-2026-11055: Use after free in ANGLE * CVE-2026-11056: Insufficient validation ofuntrusted input in SiteIsolation * CVE-2026-11057: Uninitialized Use in Skia * CVE-2026-11058: Integer overflow in CredentialProvider * CVE-2026-11059: Use after free in Blink * CVE-2026-11060: Use after free in Media * CVE-2026-11061: Out of bounds read in ANGLE * CVE-2026-11062: Insufficient policy enforcement in Extensions * CVE-2026-11063: Insufficient validation of untrusted input in WebNN * CVE-2026-11064: Uninitialized Use in GPU * CVE-2026-11065: Use after free in ANGLE * CVE-2026-11066: Insufficient validation of untrusted input in ANGLE * CVE-2026-11067: Uninitialized Use in Dawn * CVE-2026-11068: Use after free in WebSockets * CVE-2026-11069: Insufficient validation of untrusted input in Cast * CVE-2026-11070: Insufficient validation of untrusted input in Chromoting * CVE-2026-11071: Use after free in Base * CVE-2026-11072: Use after free in WebView * CVE-2026-11073: Use after free in WebGL * CVE-2026-11074: Use after free in WebRTC * CVE-2026-11075: Out of bounds read in V8 * CVE-2026-11076: Type Confusion in CSS * CVE-2026-11077: Out of bounds read in Dawn * CVE-2026-11078: Insufficient validation of untrusted input in FileSystem * CVE-2026-11079: Insufficient validation of untrusted input in Codecs * CVE-2026-11080: Use after free in WebView * CVE-2026-11081: Policy bypass in Canvas * CVE-2026-11082: Use after free in GPU * CVE-2026-11083: Inappropriate implementation in Password Manager * CVE-2026-11084: Inappropriate implementation in Password Manager * CVE-2026-11085: Integer overflow in GPU * CVE-2026-11086: Insufficient validation of untrusted input in Dawn * CVE-2026-11087: Uninitialized Use in ANGLE * CVE-2026-11088: Integer overflow in ANGLE * CVE-2026-11089: Uninitialized Use in Media * CVE-2026-11090: Uninitialized Use in ANGLE * CVE-2026-11091: Inappropriate implementation in Dawn * CVE-2026-11092: Insufficient policy enforcement in DevTools * CVE-2026-11093: Insufficient validation of untrusted input in Printing * CVE-2026-11094: Use after free in Codecs * CVE-2026-11095: Insufficient validation of untrusted input in Codecs * CVE-2026-11096: Out of bounds read in WebRTC * CVE-2026-11097: Inappropriate implementation in WebView * CVE-2026-11098: Insufficient validation of untrusted input in GPU * CVE-2026-11099: Vulnerability in Skia * CVE-2026-11100: Use after free in File Input * CVE-2026-11101: Uninitialized Use in Dawn * CVE-2026-11102: Inappropriate implementation in Isolated Web Apps * CVE-2026-11103: Inappropriate implementation in Installer * CVE-2026-11104: Uninitialized Use in ANGLE * CVE-2026-11105: Insufficient validation of untrusted input in WebUI * CVE-2026-11106: Inappropriate implementation in Media * CVE-2026-11107: Inappropriate implementation in Downloads * CVE-2026-11108: Inappropriate implementation in NFC * CVE-2026-11109: Uninitialized Use in ANGLE * CVE-2026-11110: Uninitialized Use in ANGLE * CVE-2026-11111: Out of bounds read in ANGLE * CVE-2026-11112: Insufficient validation of untrusted input in Chromoting * CVE-2026-11113: Insufficient validation of untrusted input in ANGLE * CVE-2026-11114: Use after free in Device Trust * CVE-2026-11115: Use after free in Updater * CVE-2026-11116: Use after free in Chromoting * CVE-2026-11117: Use after free in Views * CVE-2026-11118: Use after free in WebRTC * CVE-2026-11119: Insufficient validation of untrusted input in GPU * CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting * CVE-2026-11121: Insufficient validation of untrusted input in Skia * CVE-2026-11122: Inappropriate implementation in Keyboard * CVE-2026-11123: Uninitialized Use in ANGLE * CVE-2026-11124: Heap buffer overflow in Skia * CVE-2026-11125: Use after free in Compositing * CVE-2026-11126: Insufficient validation of untrusted input in DevTools * CVE-2026-11127: Inappropriate implementation in WebAPKs * CVE-2026-11128: Insufficient validation of untrusted input in Web Share *CVE-2026-11129: Inappropriate implementation in Extensions * CVE-2026-11130: Use after free in Media * CVE-2026-11131: Use after free in Autofill * CVE-2026-11132: Policy bypass in Paint * CVE-2026-11133: Insufficient policy enforcement in Paint * CVE-2026-11134: Insufficient data validation in Media * CVE-2026-11135: Insufficient policy enforcement in Autofill * CVE-2026-11136: Use after free in Canvas * CVE-2026-11137: Uninitialized Use in ANGLE * CVE-2026-11138: Uninitialized Use in ANGLE * CVE-2026-11139: Policy bypass in Paint * CVE-2026-11140: Insufficient validation of untrusted input in Chromecast * CVE-2026-11141: Uninitialized Use in Audio * CVE-2026-11142: Policy bypass in Paint * CVE-2026-11143: Heap buffer overflow in Extensions * CVE-2026-11144: Use after free in Media * CVE-2026-11145: Race in Geolocation * CVE-2026-11146: Insufficient validation of untrusted input in Chromoting * CVE-2026-11147: Use after free in WebML * CVE-2026-11148: Inappropriate implementation in Payments * CVE-2026-11149: Insufficient validation of untrusted input in Extensions * CVE-2026-11150: Inappropriate implementation in XML * CVE-2026-11151: Insufficient validation of untrusted input in Password Manager * CVE-2026-11152: Object lifecycle issue in Dawn * CVE-2026-11153: Side-channel information leakage in Forms * CVE-2026-11154: Use after free in Dawn * CVE-2026-11155: Insufficient policy enforcement in CSS * CVE-2026-11156: Inappropriate implementation in CSS * CVE-2026-11157: Script injection in Accessibility * CVE-2026-11158: Insufficient validation of untrusted input in Downloads * CVE-2026-11159: Uninitialized Use in Skia * CVE-2026-11160: Out of bounds read in Input * CVE-2026-11161: Insufficient data validation in DataTransfer * CVE-2026-11162: Insufficient policy enforcement in CSS * CVE-2026-11163: Use after free in Messages * CVE-2026-11164: Use after free in Blink * CVE-2026-11165: Use after free in WebMIDI * CVE-2026-11166:Inappropriate implementation in SVG * CVE-2026-11167: Inappropriate implementation in WebView * CVE-2026-11168: Insufficient policy enforcement in Extensions * CVE-2026-11169: Inappropriate implementation in XML * CVE-2026-11170: Inappropriate implementation in Chromoting * CVE-2026-11171: Integer overflow in Blink * CVE-2026-11172: Incorrect security UI in Contact Picker * CVE-2026-11173: Out of bounds write in V8 * CVE-2026-11174: Insufficient policy enforcement in Site Isolation * CVE-2026-11175: Incorrect security UI in Messages * CVE-2026-11176: Inappropriate implementation in Media * CVE-2026-11177: Use after free in Omnibox * CVE-2026-11178: Policy bypass in WebView * CVE-2026-11179: Inappropriate implementation in ORB * CVE-2026-11180: Policy bypass in SVG * CVE-2026-11181: Inappropriate implementation in Media Session * CVE-2026-11182: Inappropriate implementation in SVG * CVE-2026-11183: Out of bounds read in GWP-ASan * CVE-2026-11184: Insufficient policy enforcement in Actor * CVE-2026-11185: Use after free in V8 * CVE-2026-11186: Inappropriate implementation in CSS * CVE-2026-11187: Insufficient policy enforcement in Glic * CVE-2026-11188: Use after free in USB * CVE-2026-11189: Insufficient validation of untrusted input in DevTools * CVE-2026-11190: Insufficient policy enforcement in Extensions * CVE-2026-11191: Out of bounds memory access in ANGLE * CVE-2026-11192: Insufficient validation of untrusted input in Password Manager * CVE-2026-11193: Insufficient policy enforcement in Password Manager * CVE-2026-11194: Inappropriate implementation in Network * CVE-2026-11195: Inappropriate implementation in MHTML * CVE-2026-11196: Type Confusion in XML * CVE-2026-11197: Insufficient policy enforcement in Workers * CVE-2026-11198: Insufficient validation of untrusted input in Codecs * CVE-2026-11199: Insufficient validation of untrusted input in WebRTC * CVE-2026-11200: Inappropriate implementation in WebRTC * CVE-2026-11201: Use afterfree in ServiceWorker * CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11203: Policy bypass in GPU * CVE-2026-11204: Inappropriate implementation in Signin * CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11206: Policy bypass in ServiceWorker * CVE-2026-11207: Insufficient validation of untrusted input in Autofill * CVE-2026-11208: Use after free in Codecs * CVE-2026-11209: Insufficient policy enforcement in Passwords * CVE-2026-11210: Insufficient policy enforcement in Safe Browsing * CVE-2026-11211: Integer overflow in V8 * CVE-2026-11212: Insufficient policy enforcement in DevTools * CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode * CVE-2026-11214: Inappropriate implementation in Chrome for iOS * CVE-2026-11215: Inappropriate implementation in Cronet * CVE-2026-11216: Incorrect security UI in File Input * CVE-2026-11217: Insufficient policy enforcement in Fenced Frames * CVE-2026-11218: Inappropriate implementation in PlatformIntegration * CVE-2026-11219: Insufficient data validation in Navigation * CVE-2026-11220: Insufficient validation of untrusted input in Navigation * CVE-2026-11221: Insufficient validation of untrusted input in PointerLock * CVE-2026-11222: Incorrect security UI in Tab Strip * CVE-2026-11223: Insufficient validation of untrusted input in Network * CVE-2026-11224: Use after free in Chromoting * CVE-2026-11225: Incorrect security UI in WebUI * CVE-2026-11226: Insufficient policy enforcement in PreviewTab * CVE-2026-11227: Incorrect security UI in Tab Hover Cards * CVE-2026-11228: Incorrect security UI in File Input * CVE-2026-11229: Insufficient policy enforcement in Enterprise * CVE-2026-11230: Use after free in Extensions * CVE-2026-11231: Inappropriate implementation in Safe Browsing * CVE-2026-11232: Inappropriate implementation in TabGroups * CVE-2026-11233: Insufficient validation of untrusted input inFoldableAPIs * CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs * CVE-2026-11235: Insufficient validation of untrusted input in Compositing * CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth * CVE-2026-11237: Insufficient validation of untrusted input in Media * CVE-2026-11238: Inappropriate implementation in DevTools * CVE-2026-11239: Insufficient validation of untrusted input in Extensions * CVE-2026-11240: Insufficient validation of untrusted input in Loader * CVE-2026-11241: Insufficient validation of untrusted input in Cast * CVE-2026-11242: Insufficient validation of untrusted input in Plugins * CVE-2026-11243: Incorrect security UI in Downloads * CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication * CVE-2026-11245: Inappropriate implementation in Payments * CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB * CVE-2026-11247: Insufficient policy enforcement in CustomTabs * CVE-2026-11248: Policy bypass in Google Lens * CVE-2026-11249: Use after free in Network * CVE-2026-11250: Inappropriate implementation in DevTools * CVE-2026-11251: Insufficient validation of untrusted input in Password Manager * CVE-2026-11252: Policy bypass in Content Settings * CVE-2026-11253: Race in Permissions * CVE-2026-11254: Inappropriate implementation in Permissions * CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API * CVE-2026-11256: Out of bounds read in GPU * CVE-2026-11257: Inappropriate implementation in Browser * CVE-2026-11258: Inappropriate implementation in File System Access * CVE-2026-11259: Insufficient validation of untrusted input in Cast * CVE-2026-11260: Policy bypass in Permissions * CVE-2026-11261: Insufficient validation of untrusted input in PDF * CVE-2026-11262: Use after free in TabStrip * CVE-2026-11263: Insufficient policy enforcement in WebAuthentication * CVE-2026-11264: Policy bypass in Content Security Policy * CVE-2026-11265:Insufficient data validation in Autofill * CVE-2026-11266: Policy bypass in SafeBrowsing * CVE-2026-11267: Insufficient policy enforcement in Extensions * CVE-2026-11268: Uninitialized Use in ANGLE * CVE-2026-11269: Inappropriate implementation in Extensions * CVE-2026-11270: Inappropriate implementation in UI * CVE-2026-11271: Incorrect security UI in Passwords * CVE-2026-11272: Insufficient validation of untrusted input in Reading List * CVE-2026-11273: Insufficient validation of untrusted input in Omnibox * CVE-2026-11274: Inappropriate implementation in DOM Distiller * CVE-2026-11275: Insufficient policy enforcement in Page Info * CVE-2026-11276: Inappropriate implementation in Cast * CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11278: Inappropriate implementation in CustomTabs * CVE-2026-11279: Out of bounds read in DevTools * CVE-2026-11280: Insufficient validation of untrusted input in Signin * CVE-2026-11281: Integer overflow in Chromoting * CVE-2026-11282: Policy bypass in Sandbox * CVE-2026-11283: Policy bypass in Shortcuts * CVE-2026-11284: Side-channel information leakage in PerformanceAPIs * CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11286: Insufficient validation of untrusted input in Wallet * CVE-2026-11287: Insufficient validation of untrusted input in Navigation * CVE-2026-11288: Policy bypass in CSS * CVE-2026-11289: Side-channel information leakage in Paint * CVE-2026-11290: Integer overflow in WebView * CVE-2026-11291: Policy bypass in Android Autofill * CVE-2026-11292: Policy bypass in Blink * CVE-2026-11293: Use after free in Input * CVE-2026-11294: Inappropriate implementation in Passwords * CVE-2026-11295: Inappropriate implementation in WebView * CVE-2026-11296: Inappropriate implementation in ImageCapture * CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode * CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS *CVE-2026-11299: Out of bounds read in Fonts * CVE-2026-11300: Inappropriate implementation in Permissions * CVE-2026-11301: Out of bounds read in LiveCaption * CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11303: Use after free in PDFium * CVE-2026-11304: Use after free in PDFium * CVE-2026-11305: Use after free in PDFium * CVE-2026-11306: Use after free in PDFium * CVE-2026-11307: Use after free in PDFium * CVE-2026-11308: Inappropriate implementation in Extensions * CVE-2026-11309: Insufficient policy enforcement in History Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-301=1 Package List: - openSUSE Leap 16.0: chromedriver-149.0.7827.53-bp160.1.1 chromium-149.0.7827.53-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-10881.html * https://www.suse.com/security/cve/CVE-2026-10882.html * https://www.suse.com/security/cve/CVE-2026-10883.html * https://www.suse.com/security/cve/CVE-2026-10884.html * https://www.suse.com/security/cve/CVE-2026-10885.html * https://www.suse.com/security/cve/CVE-2026-10886.html * https://www.suse.com/security/cve/CVE-2026-10887.html * https://www.suse.com/security/cve/CVE-2026-10888.html * https://www.suse.com/security/cve/CVE-2026-10889.html * https://www.suse.com/security/cve/CVE-2026-10890.html * https://www.suse.com/security/cve/CVE-2026-10891.html * https://www.suse.com/security/cve/CVE-2026-10892.html * https://www.suse.com/security/cve/CVE-2026-10893.html * https://www.suse.com/security/cve/CVE-2026-10894.html * https://www.suse.com/security/cve/CVE-2026-10895.html * https://www.suse.com/security/cve/CVE-2026-10896.html * https://www.suse.com/security/cve/CVE-2026-10897.html *https://www.suse.com/security/cve/CVE-2026-10898.html * https://www.suse.com/security/cve/CVE-2026-10899.html * https://www.suse.com/security/cve/CVE-2026-10900.html * https://www.suse.com/security/cve/CVE-2026-10901.html * https://www.suse.com/security/cve/CVE-2026-10902.html * https://www.suse.com/security/cve/CVE-2026-10903.html * https://www.suse.com/security/cve/CVE-2026-10904.html * https://www.suse.com/security/cve/CVE-2026-10905.html * https://www.suse.com/security/cve/CVE-2026-10906.html * https://www.suse.com/security/cve/CVE-2026-10907.html * https://www.suse.com/security/cve/CVE-2026-10908.html * https://www.suse.com/security/cve/CVE-2026-10909.html * https://www.suse.com/security/cve/CVE-2026-10910.html * https://www.suse.com/security/cve/CVE-2026-10911.html * https://www.suse.com/security/cve/CVE-2026-10912.html * https://www.suse.com/security/cve/CVE-2026-10913.html * https://www.suse.com/security/cve/CVE-2026-10914.html * https://www.suse.com/security/cve/CVE-2026-10915.html * https://www.suse.com/security/cve/CVE-2026-10916.html * https://www.suse.com/security/cve/CVE-2026-10917.html * https://www.suse.com/security/cve/CVE-2026-10918.html * https://www.suse.com/security/cve/CVE-2026-10919.html * https://www.suse.com/security/cve/CVE-2026-10920.html * https://www.suse.com/security/cve/CVE-2026-10921.html * https://www.suse.com/security/cve/CVE-2026-10922.html * https://www.suse.com/security/cve/CVE-2026-10923.html * https://www.suse.com/security/cve/CVE-2026-10924.html * https://www.suse.com/security/cve/CVE-2026-10925.html * https://www.suse.com/security/cve/CVE-2026-10926.html * https://www.suse.com/security/cve/CVE-2026-10927.html * https://www.suse.com/security/cve/CVE-2026-10928.html * https://www.suse.com/security/cve/CVE-2026-10929.html * https://www.suse.com/security/cve/CVE-2026-10930.html * https://www.suse.com/security/cve/CVE-2026-10931.html * https://www.suse.com/security/cve/CVE-2026-10932.html *https://www.suse.com/security/cve/CVE-2026-10933.html * https://www.suse.com/security/cve/CVE-2026-10934.html * https://www.suse.com/security/cve/CVE-2026-10935.html * https://www.suse.com/security/cve/CVE-2026-10936.html * https://www.suse.com/security/cve/CVE-2026-10937.html * https://www.suse.com/security/cve/CVE-2026-10938.html * https://www.suse.com/security/cve/CVE-2026-10939.html * https://www.suse.com/security/cve/CVE-2026-10940.html * https://www.suse.com/security/cve/CVE-2026-10941.html * https://www.suse.com/security/cve/CVE-2026-10942.html * https://www.suse.com/security/cve/CVE-2026-10943.html * https://www.suse.com/security/cve/CVE-2026-10944.html * https://www.suse.com/security/cve/CVE-2026-10945.html * https://www.suse.com/security/cve/CVE-2026-10946.html * https://www.suse.com/security/cve/CVE-2026-10947.html * https://www.suse.com/security/cve/CVE-2026-10948.html * https://www.suse.com/security/cve/CVE-2026-10949.html * https://www.suse.com/security/cve/CVE-2026-10950.html * https://www.suse.com/security/cve/CVE-2026-10951.html * https://www.suse.com/security/cve/CVE-2026-10952.html * https://www.suse.com/security/cve/CVE-2026-10953.html * https://www.suse.com/security/cve/CVE-2026-10954.html * https://www.suse.com/security/cve/CVE-2026-10955.html * https://www.suse.com/security/cve/CVE-2026-10956.html * https://www.suse.com/security/cve/CVE-2026-10957.html * https://www.suse.com/security/cve/CVE-2026-10958.html * https://www.suse.com/security/cve/CVE-2026-10959.html * https://www.suse.com/security/cve/CVE-2026-10960.html * https://www.suse.com/security/cve/CVE-2026-10961.html * https://www.suse.com/security/cve/CVE-2026-10962.html * https://www.suse.com/security/cve/CVE-2026-10963.html * https://www.suse.com/security/cve/CVE-2026-10964.html * https://www.suse.com/security/cve/CVE-2026-10965.html * https://www.suse.com/security/cve/CVE-2026-10966.html * https://www.suse.com/security/cve/CVE-2026-10967.html *https://www.suse.com/security/cve/CVE-2026-10968.html * https://www.suse.com/security/cve/CVE-2026-10969.html * https://www.suse.com/security/cve/CVE-2026-10970.html * https://www.suse.com/security/cve/CVE-2026-10971.html * https://www.suse.com/security/cve/CVE-2026-10972.html * https://www.suse.com/security/cve/CVE-2026-10973.html * https://www.suse.com/security/cve/CVE-2026-10974.html * https://www.suse.com/security/cve/CVE-2026-10975.html * https://www.suse.com/security/cve/CVE-2026-10976.html * https://www.suse.com/security/cve/CVE-2026-10977.html * https://www.suse.com/security/cve/CVE-2026-10978.html * https://www.suse.com/security/cve/CVE-2026-10979.html * https://www.suse.com/security/cve/CVE-2026-10980.html * https://www.suse.com/security/cve/CVE-2026-10981.html * https://www.suse.com/security/cve/CVE-2026-10982.html * https://www.suse.com/security/cve/CVE-2026-10983.html * https://www.suse.com/security/cve/CVE-2026-10984.html * https://www.suse.com/security/cve/CVE-2026-10985.html * https://www.suse.com/security/cve/CVE-2026-10986.html * https://www.suse.com/security/cve/CVE-2026-10987.html * https://www.suse.com/security/cve/CVE-2026-10988.html * https://www.suse.com/security/cve/CVE-2026-10989.html * https://www.suse.com/security/cve/CVE-2026-10990.html * https://www.suse.com/security/cve/CVE-2026-10991.html * https://www.suse.com/security/cve/CVE-2026-10992.html * https://www.suse.com/security/cve/CVE-2026-10993.html * https://www.suse.com/security/cve/CVE-2026-10994.html * https://www.suse.com/security/cve/CVE-2026-10995.html * https://www.suse.com/security/cve/CVE-2026-10996.html * https://www.suse.com/security/cve/CVE-2026-10997.html * https://www.suse.com/security/cve/CVE-2026-10998.html * https://www.suse.com/security/cve/CVE-2026-10999.html * https://www.suse.com/security/cve/CVE-2026-11000.html * https://www.suse.com/security/cve/CVE-2026-11001.html * https://www.suse.com/security/cve/CVE-2026-11002.html *https://www.suse.com/security/cve/CVE-2026-11003.html * https://www.suse.com/security/cve/CVE-2026-11004.html * https://www.suse.com/security/cve/CVE-2026-11005.html * https://www.suse.com/security/cve/CVE-2026-11006.html * https://www.suse.com/security/cve/CVE-2026-11007.html * https://www.suse.com/security/cve/CVE-2026-11008.html * https://www.suse.com/security/cve/CVE-2026-11009.html * https://www.suse.com/security/cve/CVE-2026-11010.html * https://www.suse.com/security/cve/CVE-2026-11011.html * https://www.suse.com/security/cve/CVE-2026-11012.html * https://www.suse.com/security/cve/CVE-2026-11013.html * https://www.suse.com/security/cve/CVE-2026-11014.html * https://www.suse.com/security/cve/CVE-2026-11015.html * https://www.suse.com/security/cve/CVE-2026-11016.html * https://www.suse.com/security/cve/CVE-2026-11017.html * https://www.suse.com/security/cve/CVE-2026-11018.html * https://www.suse.com/security/cve/CVE-2026-11019.html * https://www.suse.com/security/cve/CVE-2026-11020.html * https://www.suse.com/security/cve/CVE-2026-11021.html * https://www.suse.com/security/cve/CVE-2026-11022.html * https://www.suse.com/security/cve/CVE-2026-11023.html * https://www.suse.com/security/cve/CVE-2026-11024.html * https://www.suse.com/security/cve/CVE-2026-11025.html * https://www.suse.com/security/cve/CVE-2026-11026.html * https://www.suse.com/security/cve/CVE-2026-11027.html * https://www.suse.com/security/cve/CVE-2026-11028.html * https://www.suse.com/security/cve/CVE-2026-11029.html * https://www.suse.com/security/cve/CVE-2026-11030.html * https://www.suse.com/security/cve/CVE-2026-11031.html * https://www.suse.com/security/cve/CVE-2026-11032.html * https://www.suse.com/security/cve/CVE-2026-11033.html * https://www.suse.com/security/cve/CVE-2026-11034.html * https://www.suse.com/security/cve/CVE-2026-11035.html * https://www.suse.com/security/cve/CVE-2026-11036.html * https://www.suse.com/security/cve/CVE-2026-11037.html *https://www.suse.com/security/cve/CVE-2026-11038.html * https://www.suse.com/security/cve/CVE-2026-11039.html * https://www.suse.com/security/cve/CVE-2026-11040.html * https://www.suse.com/security/cve/CVE-2026-11041.html * https://www.suse.com/security/cve/CVE-2026-11042.html * https://www.suse.com/security/cve/CVE-2026-11043.html * https://www.suse.com/security/cve/CVE-2026-11044.html * https://www.suse.com/security/cve/CVE-2026-11045.html * https://www.suse.com/security/cve/CVE-2026-11046.html * https://www.suse.com/security/cve/CVE-2026-11047.html * https://www.suse.com/security/cve/CVE-2026-11048.html * https://www.suse.com/security/cve/CVE-2026-11049.html * https://www.suse.com/security/cve/CVE-2026-11050.html * https://www.suse.com/security/cve/CVE-2026-11051.html * https://www.suse.com/security/cve/CVE-2026-11052.html * https://www.suse.com/security/cve/CVE-2026-11053.html * https://www.suse.com/security/cve/CVE-2026-11054.html * https://www.suse.com/security/cve/CVE-2026-11055.html * https://www.suse.com/security/cve/CVE-2026-11056.html * https://www.suse.com/security/cve/CVE-2026-11057.html * https://www.suse.com/security/cve/CVE-2026-11058.html * https://www.suse.com/security/cve/CVE-2026-11059.html * https://www.suse.com/security/cve/CVE-2026-11060.html * https://www.suse.com/security/cve/CVE-2026-11061.html * https://www.suse.com/security/cve/CVE-2026-11062.html * https://www.suse.com/security/cve/CVE-2026-11063.html * https://www.suse.com/security/cve/CVE-2026-11064.html * https://www.suse.com/security/cve/CVE-2026-11065.html * https://www.suse.com/security/cve/CVE-2026-11066.html * https://www.suse.com/security/cve/CVE-2026-11067.html * https://www.suse.com/security/cve/CVE-2026-11068.html * https://www.suse.com/security/cve/CVE-2026-11069.html * https://www.suse.com/security/cve/CVE-2026-11070.html * https://www.suse.com/security/cve/CVE-2026-11071.html * https://www.suse.com/security/cve/CVE-2026-11072.html *https://www.suse.com/security/cve/CVE-2026-11073.html * https://www.suse.com/security/cve/CVE-2026-11074.html * https://www.suse.com/security/cve/CVE-2026-11075.html * https://www.suse.com/security/cve/CVE-2026-11076.html * https://www.suse.com/security/cve/CVE-2026-11077.html * https://www.suse.com/security/cve/CVE-2026-11078.html * https://www.suse.com/security/cve/CVE-2026-11079.html * https://www.suse.com/security/cve/CVE-2026-11080.html * https://www.suse.com/security/cve/CVE-2026-11081.html * https://www.suse.com/security/cve/CVE-2026-11082.html * https://www.suse.com/security/cve/CVE-2026-11083.html * https://www.suse.com/security/cve/CVE-2026-11084.html * https://www.suse.com/security/cve/CVE-2026-11085.html * https://www.suse.com/security/cve/CVE-2026-11086.html * https://www.suse.com/security/cve/CVE-2026-11087.html * https://www.suse.com/security/cve/CVE-2026-11088.html * https://www.suse.com/security/cve/CVE-2026-11089.html * https://www.suse.com/security/cve/CVE-2026-11090.html * https://www.suse.com/security/cve/CVE-2026-11091.html * https://www.suse.com/security/cve/CVE-2026-11092.html * https://www.suse.com/security/cve/CVE-2026-11093.html * https://www.suse.com/security/cve/CVE-2026-11094.html * https://www.suse.com/security/cve/CVE-2026-11095.html * https://www.suse.com/security/cve/CVE-2026-11096.html * https://www.suse.com/security/cve/CVE-2026-11097.html * https://www.suse.com/security/cve/CVE-2026-11098.html * https://www.suse.com/security/cve/CVE-2026-11099.html * https://www.suse.com/security/cve/CVE-2026-11100.html * https://www.suse.com/security/cve/CVE-2026-11101.html * https://www.suse.com/security/cve/CVE-2026-11102.html * https://www.suse.com/security/cve/CVE-2026-11103.html * https://www.suse.com/security/cve/CVE-2026-11104.html * https://www.suse.com/security/cve/CVE-2026-11105.html * https://www.suse.com/security/cve/CVE-2026-11106.html * https://www.suse.com/security/cve/CVE-2026-11107.html *https://www.suse.com/security/cve/CVE-2026-11108.html * https://www.suse.com/security/cve/CVE-2026-11109.html * https://www.suse.com/security/cve/CVE-2026-11110.html * https://www.suse.com/security/cve/CVE-2026-11111.html * https://www.suse.com/security/cve/CVE-2026-11112.html * https://www.suse.com/security/cve/CVE-2026-11113.html * https://www.suse.com/security/cve/CVE-2026-11114.html * https://www.suse.com/security/cve/CVE-2026-11115.html * https://www.suse.com/security/cve/CVE-2026-11116.html * https://www.suse.com/security/cve/CVE-2026-11117.html * https://www.suse.com/security/cve/CVE-2026-11118.html * https://www.suse.com/security/cve/CVE-2026-11119.html * https://www.suse.com/security/cve/CVE-2026-11120.html * https://www.suse.com/security/cve/CVE-2026-11121.html * https://www.suse.com/security/cve/CVE-2026-11122.html * https://www.suse.com/security/cve/CVE-2026-11123.html * https://www.suse.com/security/cve/CVE-2026-11124.html * https://www.suse.com/security/cve/CVE-2026-11125.html * https://www.suse.com/security/cve/CVE-2026-11126.html * https://www.suse.com/security/cve/CVE-2026-11127.html * https://www.suse.com/security/cve/CVE-2026-11128.html * https://www.suse.com/security/cve/CVE-2026-11129.html * https://www.suse.com/security/cve/CVE-2026-11130.html * https://www.suse.com/security/cve/CVE-2026-11131.html * https://www.suse.com/security/cve/CVE-2026-11132.html * https://www.suse.com/security/cve/CVE-2026-11133.html * https://www.suse.com/security/cve/CVE-2026-11134.html * https://www.suse.com/security/cve/CVE-2026-11135.html * https://www.suse.com/security/cve/CVE-2026-11136.html * https://www.suse.com/security/cve/CVE-2026-11137.html * https://www.suse.com/security/cve/CVE-2026-11138.html * https://www.suse.com/security/cve/CVE-2026-11139.html * https://www.suse.com/security/cve/CVE-2026-11140.html * https://www.suse.com/security/cve/CVE-2026-11141.html * https://www.suse.com/security/cve/CVE-2026-11142.html *https://www.suse.com/security/cve/CVE-2026-11143.html * https://www.suse.com/security/cve/CVE-2026-11144.html * https://www.suse.com/security/cve/CVE-2026-11145.html * https://www.suse.com/security/cve/CVE-2026-11146.html * https://www.suse.com/security/cve/CVE-2026-11147.html * https://www.suse.com/security/cve/CVE-2026-11148.html * https://www.suse.com/security/cve/CVE-2026-11149.html * https://www.suse.com/security/cve/CVE-2026-11150.html * https://www.suse.com/security/cve/CVE-2026-11151.html * https://www.suse.com/security/cve/CVE-2026-11152.html * https://www.suse.com/security/cve/CVE-2026-11153.html * https://www.suse.com/security/cve/CVE-2026-11154.html * https://www.suse.com/security/cve/CVE-2026-11155.html * https://www.suse.com/security/cve/CVE-2026-11156.html * https://www.suse.com/security/cve/CVE-2026-11157.html * https://www.suse.com/security/cve/CVE-2026-11158.html * https://www.suse.com/security/cve/CVE-2026-11159.html * https://www.suse.com/security/cve/CVE-2026-11160.html * https://www.suse.com/security/cve/CVE-2026-11161.html * https://www.suse.com/security/cve/CVE-2026-11162.html * https://www.suse.com/security/cve/CVE-2026-11163.html * https://www.suse.com/security/cve/CVE-2026-11164.html * https://www.suse.com/security/cve/CVE-2026-11165.html * https://www.suse.com/security/cve/CVE-2026-11166.html * https://www.suse.com/security/cve/CVE-2026-11167.html * https://www.suse.com/security/cve/CVE-2026-11168.html * https://www.suse.com/security/cve/CVE-2026-11169.html * https://www.suse.com/security/cve/CVE-2026-11170.html * https://www.suse.com/security/cve/CVE-2026-11171.html * https://www.suse.com/security/cve/CVE-2026-11172.html * https://www.suse.com/security/cve/CVE-2026-11173.html * https://www.suse.com/security/cve/CVE-2026-11174.html * https://www.suse.com/security/cve/CVE-2026-11175.html * https://www.suse.com/security/cve/CVE-2026-11176.html * https://www.suse.com/security/cve/CVE-2026-11177.html *https://www.suse.com/security/cve/CVE-2026-11178.html * https://www.suse.com/security/cve/CVE-2026-11179.html * https://www.suse.com/security/cve/CVE-2026-11180.html * https://www.suse.com/security/cve/CVE-2026-11181.html * https://www.suse.com/security/cve/CVE-2026-11182.html * https://www.suse.com/security/cve/CVE-2026-11183.html * https://www.suse.com/security/cve/CVE-2026-11184.html * https://www.suse.com/security/cve/CVE-2026-11185.html * https://www.suse.com/security/cve/CVE-2026-11186.html * https://www.suse.com/security/cve/CVE-2026-11187.html * https://www.suse.com/security/cve/CVE-2026-11188.html * https://www.suse.com/security/cve/CVE-2026-11189.html * https://www.suse.com/security/cve/CVE-2026-11190.html * https://www.suse.com/security/cve/CVE-2026-11191.html * https://www.suse.com/security/cve/CVE-2026-11192.html * https://www.suse.com/security/cve/CVE-2026-11193.html * https://www.suse.com/security/cve/CVE-2026-11194.html * https://www.suse.com/security/cve/CVE-2026-11195.html * https://www.suse.com/security/cve/CVE-2026-11196.html * https://www.suse.com/security/cve/CVE-2026-11197.html * https://www.suse.com/security/cve/CVE-2026-11198.html * https://www.suse.com/security/cve/CVE-2026-11199.html * https://www.suse.com/security/cve/CVE-2026-11200.html * https://www.suse.com/security/cve/CVE-2026-11201.html * https://www.suse.com/security/cve/CVE-2026-11202.html * https://www.suse.com/security/cve/CVE-2026-11203.html * https://www.suse.com/security/cve/CVE-2026-11204.html * https://www.suse.com/security/cve/CVE-2026-11205.html * https://www.suse.com/security/cve/CVE-2026-11206.html * https://www.suse.com/security/cve/CVE-2026-11207.html * https://www.suse.com/security/cve/CVE-2026-11208.html * https://www.suse.com/security/cve/CVE-2026-11209.html * https://www.suse.com/security/cve/CVE-2026-11210.html * https://www.suse.com/security/cve/CVE-2026-11211.html * https://www.suse.com/security/cve/CVE-2026-11212.html *https://www.suse.com/security/cve/CVE-2026-11213.html * https://www.suse.com/security/cve/CVE-2026-11214.html * https://www.suse.com/security/cve/CVE-2026-11215.html * https://www.suse.com/security/cve/CVE-2026-11216.html * https://www.suse.com/security/cve/CVE-2026-11217.html * https://www.suse.com/security/cve/CVE-2026-11218.html * https://www.suse.com/security/cve/CVE-2026-11219.html * https://www.suse.com/security/cve/CVE-2026-11220.html * https://www.suse.com/security/cve/CVE-2026-11221.html * https://www.suse.com/security/cve/CVE-2026-11222.html * https://www.suse.com/security/cve/CVE-2026-11223.html * https://www.suse.com/security/cve/CVE-2026-11224.html * https://www.suse.com/security/cve/CVE-2026-11225.html * https://www.suse.com/security/cve/CVE-2026-11226.html * https://www.suse.com/security/cve/CVE-2026-11227.html * https://www.suse.com/security/cve/CVE-2026-11228.html * https://www.suse.com/security/cve/CVE-2026-11229.html * https://www.suse.com/security/cve/CVE-2026-11230.html * https://www.suse.com/security/cve/CVE-2026-11231.html * https://www.suse.com/security/cve/CVE-2026-11232.html * https://www.suse.com/security/cve/CVE-2026-11233.html * https://www.suse.com/security/cve/CVE-2026-11234.html * https://www.suse.com/security/cve/CVE-2026-11235.html * https://www.suse.com/security/cve/CVE-2026-11236.html * https://www.suse.com/security/cve/CVE-2026-11237.html * https://www.suse.com/security/cve/CVE-2026-11238.html * https://www.suse.com/security/cve/CVE-2026-11239.html * https://www.suse.com/security/cve/CVE-2026-11240.html * https://www.suse.com/security/cve/CVE-2026-11241.html * https://www.suse.com/security/cve/CVE-2026-11242.html * https://www.suse.com/security/cve/CVE-2026-11243.html * https://www.suse.com/security/cve/CVE-2026-11244.html * https://www.suse.com/security/cve/CVE-2026-11245.html * https://www.suse.com/security/cve/CVE-2026-11246.html * https://www.suse.com/security/cve/CVE-2026-11247.html *https://www.suse.com/security/cve/CVE-2026-11248.html * https://www.suse.com/security/cve/CVE-2026-11249.html * https://www.suse.com/security/cve/CVE-2026-11250.html * https://www.suse.com/security/cve/CVE-2026-11251.html * https://www.suse.com/security/cve/CVE-2026-11252.html * https://www.suse.com/security/cve/CVE-2026-11253.html * https://www.suse.com/security/cve/CVE-2026-11254.html * https://www.suse.com/security/cve/CVE-2026-11255.html * https://www.suse.com/security/cve/CVE-2026-11256.html * https://www.suse.com/security/cve/CVE-2026-11257.html * https://www.suse.com/security/cve/CVE-2026-11258.html * https://www.suse.com/security/cve/CVE-2026-11259.html * https://www.suse.com/security/cve/CVE-2026-11260.html * https://www.suse.com/security/cve/CVE-2026-11261.html * https://www.suse.com/security/cve/CVE-2026-11262.html * https://www.suse.com/security/cve/CVE-2026-11263.html * https://www.suse.com/security/cve/CVE-2026-11264.html * https://www.suse.com/security/cve/CVE-2026-11265.html * https://www.suse.com/security/cve/CVE-2026-11266.html * https://www.suse.com/security/cve/CVE-2026-11267.html * https://www.suse.com/security/cve/CVE-2026-11268.html * https://www.suse.com/security/cve/CVE-2026-11269.html * https://www.suse.com/security/cve/CVE-2026-11270.html * https://www.suse.com/security/cve/CVE-2026-11271.html * https://www.suse.com/security/cve/CVE-2026-11272.html * https://www.suse.com/security/cve/CVE-2026-11273.html * https://www.suse.com/security/cve/CVE-2026-11274.html * https://www.suse.com/security/cve/CVE-2026-11275.html * https://www.suse.com/security/cve/CVE-2026-11276.html * https://www.suse.com/security/cve/CVE-2026-11277.html * https://www.suse.com/security/cve/CVE-2026-11278.html * https://www.suse.com/security/cve/CVE-2026-11279.html * https://www.suse.com/security/cve/CVE-2026-11280.html * https://www.suse.com/security/cve/CVE-2026-11281.html * https://www.suse.com/security/cve/CVE-2026-11282.html *https://www.suse.com/security/cve/CVE-2026-11283.html * https://www.suse.com/security/cve/CVE-2026-11284.html * https://www.suse.com/security/cve/CVE-2026-11285.html * https://www.suse.com/security/cve/CVE-2026-11286.html * https://www.suse.com/security/cve/CVE-2026-11287.html * https://www.suse.com/security/cve/CVE-2026-11288.html * https://www.suse.com/security/cve/CVE-2026-11289.html * https://www.suse.com/security/cve/CVE-2026-11290.html * https://www.suse.com/security/cve/CVE-2026-11291.html * https://www.suse.com/security/cve/CVE-2026-11292.html * https://www.suse.com/security/cve/CVE-2026-11293.html * https://www.suse.com/security/cve/CVE-2026-11294.html * https://www.suse.com/security/cve/CVE-2026-11295.html * https://www.suse.com/security/cve/CVE-2026-11296.html * https://www.suse.com/security/cve/CVE-2026-11297.html * https://www.suse.com/security/cve/CVE-2026-11298.html * https://www.suse.com/security/cve/CVE-2026-11299.html * https://www.suse.com/security/cve/CVE-2026-11300.html * https://www.suse.com/security/cve/CVE-2026-11301.html * https://www.suse.com/security/cve/CVE-2026-11302.html * https://www.suse.com/security/cve/CVE-2026-11303.html * https://www.suse.com/security/cve/CVE-2026-11304.html * https://www.suse.com/security/cve/CVE-2026-11305.html * https://www.suse.com/security/cve/CVE-2026-11306.html * https://www.suse.com/security/cve/CVE-2026-11307.html * https://www.suse.com/security/cve/CVE-2026-11308.html * https://www.suse.com/security/cve/CVE-2026-11309.html . Update for openSUSE Chromium addresses 429 issues, critical patch needed for stability and security threats.. openSUSE Chromium security fix vulnerabilities patch. . Severity: Critical. LinuxSecurity.com Team
* bsc#1225905 Cross-References: * CVE-2024-35221 . # Security update for ruby2.5 Announcement ID: SUSE-SU-2025:02814-2 Release Date: 2025-09-04T09:16:59Z Rating: moderate References: * bsc#1225905 Cross-References: * CVE-2024-35221 CVSS scores: * CVE-2024-35221 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS An update that solves one vulnerability can now be installed. ## Description: This update for ruby2.5 fixes the following issues: * CVE-2024-35221: Fixed remote denial of service via YAML manifest (bsc#1225905) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-2814=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-2814=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-2814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-2814=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-2814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-2814=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-2814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-2814=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-2814=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-2814=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-2814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-2814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-2814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-2814=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-2814=1 ## Package List: * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 *ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Manager Server 4.3 LTS (ppc64le s390x x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 *ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE LinuxEnterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 * SUSE Manager Proxy 4.3 LTS (x86_64) * ruby2.5-devel-extra-2.5.9-150000.4.49.1 * libruby2_5-2_5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-stdlib-2.5.9-150000.4.49.1 * ruby2.5-stdlib-debuginfo-2.5.9-150000.4.49.1 * ruby2.5-devel-2.5.9-150000.4.49.1 * ruby2.5-2.5.9-150000.4.49.1 * libruby2_5-2_5-2.5.9-150000.4.49.1 * ruby2.5-debugsource-2.5.9-150000.4.49.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35221.html * https://bugzilla.suse.com/show_bug.cgi?id=1225905 . Critical update for ruby2.5 available on SUSE, addressing a potential remote downtime threat to enhance system security. Ensure to implement this fix without delay!. SUSE, ruby2.5, update, security patch, Denial of Service. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 30 for SLE 15 SP1) ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3061-1 Rating: important References: #1196867 #1201941 Cross-References: CVE-2020-36516 CVE-2022-36946 CVSS scores: CVE-2020-36516 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L CVE-2020-36516 (SUSE): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H CVE-2022-36946 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-36946 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15 SUSE Linux Enterprise High Performance Computing 15-SP1 SUSE Linux Enterprise High Performance Computing 15-SP2 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Live Patching 12-SP4 SUSE Linux Enterprise Live Patching 12-SP5 SUSE Linux Enterprise Micro 5.1 SUSE Linux Enterprise Module for Live Patching 15 SUSE Linux Enterprise Module for Live Patching 15-SP1 SUSE Linux Enterprise Module for Live Patching 15-SP2 SUSE Linux Enterprise Module for Live Patching 15-SP3 SUSE Linux Enterprise Server 15 SUSE Linux Enterprise Server 15-SP1 SUSE Linux Enterprise Server 15-SP2 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15 SUSE Linux Enterprise Server for SAP Applications 15-SP1 SUSE Linux Enterprise Server for SAP Applications 15-SP2 SUSE LinuxEnterprise Server for SAP Applications 15-SP3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 4.12.14-150100_197_111 fixes several issues. The following security issues were fixed: - CVE-2020-36516: Fixed an off-path attack via mixed IPID assignment method with the hash-based IPID assignment policy to inject data into a victim's TCP session or terminate that session (bsc#1196867). - CVE-2022-36946: Fixed a remote denial of service attack inside nfqnl_mangle in net/netfilter/nfnetlink_queue.c, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative length (bsc#1201941). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP3: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2022-3066=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3067=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3068=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3069=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3070=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3071=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3073=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3074=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3076=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3078=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3079=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3083=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3110=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3111=1 SUSE-SLE-Module-Live-Patching-15-SP3-2022-3120=1 - SUSE Linux Enterprise Module for Live Patching 15-SP2: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP2-2022-3065=1 SUSE-SLE-Module-Live-Patching-15-SP2-2022-3077=1SUSE-SLE-Module-Live-Patching-15-SP2-2022-3081=1 SUSE-SLE-Module-Live-Patching-15-SP2-2022-3082=1 SUSE-SLE-Module-Live-Patching-15-SP2-2022-3084=1 SUSE-SLE-Module-Live-Patching-15-SP2-2022-3085=1 SUSE-SLE-Module-Live-Patching-15-SP2-2022-3090=1 SUSE-SLE-Module-Live-Patching-15-SP2-2022-3104=1 SUSE-SLE-Module-Live-Patching-15-SP2-2022-3109=1 - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2022-3058=1 SUSE-SLE-Module-Live-Patching-15-SP1-2022-3059=1 SUSE-SLE-Module-Live-Patching-15-SP1-2022-3060=1 SUSE-SLE-Module-Live-Patching-15-SP1-2022-3061=1 SUSE-SLE-Module-Live-Patching-15-SP1-2022-3062=1 SUSE-SLE-Module-Live-Patching-15-SP1-2022-3063=1 - SUSE Linux Enterprise Module for Live Patching 15: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-2022-3052=1 SUSE-SLE-Module-Live-Patching-15-2022-3053=1 SUSE-SLE-Module-Live-Patching-15-2022-3054=1 SUSE-SLE-Module-Live-Patching-15-2022-3055=1 SUSE-SLE-Module-Live-Patching-15-2022-3056=1 SUSE-SLE-Module-Live-Patching-15-2022-3121=1 - SUSE Linux Enterprise Live Patching 12-SP5: zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2022-3040=1 SUSE-SLE-Live-Patching-12-SP5-2022-3041=1 SUSE-SLE-Live-Patching-12-SP5-2022-3042=1 SUSE-SLE-Live-Patching-12-SP5-2022-3043=1 SUSE-SLE-Live-Patching-12-SP5-2022-3044=1 SUSE-SLE-Live-Patching-12-SP5-2022-3045=1 SUSE-SLE-Live-Patching-12-SP5-2022-3046=1 SUSE-SLE-Live-Patching-12-SP5-2022-3047=1 SUSE-SLE-Live-Patching-12-SP5-2022-3048=1 SUSE-SLE-Live-Patching-12-SP5-2022-3049=1 SUSE-SLE-Live-Patching-12-SP5-2022-3050=1 - SUSE Linux Enterprise Live Patching 12-SP4: zypper in -t patch SUSE-SLE-Live-Patching-12-SP4-2022-3033=1 SUSE-SLE-Live-Patching-12-SP4-2022-3034=1 SUSE-SLE-Live-Patching-12-SP4-2022-3035=1 SUSE-SLE-Live-Patching-12-SP4-2022-3036=1 SUSE-SLE-Live-Patching-12-SP4-2022-3037=1 SUSE-SLE-Live-Patching-12-SP4-2022-3038=1 SUSE-SLE-Live-Patching-12-SP4-2022-3039=1 Package List: - SUSE Linux Enterprise Module for LivePatching 15-SP3 (ppc64le s390x x86_64): kernel-livepatch-5_3_18-150300_59_43-default-13-150300.2.2 kernel-livepatch-5_3_18-150300_59_43-default-debuginfo-13-150300.2.2 kernel-livepatch-5_3_18-150300_59_46-default-13-150300.2.2 kernel-livepatch-5_3_18-150300_59_46-default-debuginfo-13-150300.2.2 kernel-livepatch-5_3_18-150300_59_49-default-12-150300.2.2 kernel-livepatch-5_3_18-150300_59_54-default-11-150300.2.2 kernel-livepatch-5_3_18-150300_59_60-default-10-150300.2.2 kernel-livepatch-5_3_18-150300_59_63-default-7-150300.2.2 kernel-livepatch-5_3_18-150300_59_68-default-6-150300.2.2 kernel-livepatch-5_3_18-150300_59_71-default-5-150300.2.1 kernel-livepatch-5_3_18-150300_59_76-default-4-150300.2.1 kernel-livepatch-5_3_18-150300_59_87-default-3-150300.2.1 kernel-livepatch-5_3_18-59_24-default-16-150300.2.2 kernel-livepatch-5_3_18-59_24-default-debuginfo-16-150300.2.2 kernel-livepatch-5_3_18-59_27-default-16-150300.2.2 kernel-livepatch-5_3_18-59_27-default-debuginfo-16-150300.2.2 kernel-livepatch-5_3_18-59_34-default-15-150300.2.2 kernel-livepatch-5_3_18-59_34-default-debuginfo-15-150300.2.2 kernel-livepatch-5_3_18-59_37-default-14-150300.2.2 kernel-livepatch-5_3_18-59_37-default-debuginfo-14-150300.2.2 kernel-livepatch-5_3_18-59_40-default-14-150300.2.2 kernel-livepatch-SLE15-SP3_Update_10-debugsource-14-150300.2.2 kernel-livepatch-SLE15-SP3_Update_6-debugsource-16-150300.2.2 kernel-livepatch-SLE15-SP3_Update_7-debugsource-16-150300.2.2 kernel-livepatch-SLE15-SP3_Update_9-debugsource-15-150300.2.2 - SUSE Linux Enterprise Module for Live Patching 15-SP3 (ppc64le x86_64): kernel-livepatch-5_3_18-59_40-default-debuginfo-14-150300.2.2 - SUSE Linux Enterprise Module for Live Patching 15-SP2 (ppc64le s390x x86_64): kernel-livepatch-5_3_18-150200_24_112-default-7-150200.2.2 kernel-livepatch-5_3_18-150200_24_112-default-debuginfo-7-150200.2.2 kernel-livepatch-5_3_18-150200_24_115-default-5-150200.2.1 kernel-livepatch-5_3_18-150200_24_115-default-debuginfo-5-150200.2.1 kernel-livepatch-5_3_18-24_102-default-12-150200.2.2 kernel-livepatch-5_3_18-24_102-default-debuginfo-12-150200.2.2 kernel-livepatch-5_3_18-24_107-default-11-150200.2.2 kernel-livepatch-5_3_18-24_107-default-debuginfo-11-150200.2.2 kernel-livepatch-5_3_18-24_83-default-16-150200.2.2 kernel-livepatch-5_3_18-24_83-default-debuginfo-16-150200.2.2 kernel-livepatch-5_3_18-24_86-default-16-150200.2.2 kernel-livepatch-5_3_18-24_86-default-debuginfo-16-150200.2.2 kernel-livepatch-5_3_18-24_93-default-15-150200.2.2 kernel-livepatch-5_3_18-24_93-default-debuginfo-15-150200.2.2 kernel-livepatch-5_3_18-24_96-default-14-150200.2.2 kernel-livepatch-5_3_18-24_96-default-debuginfo-14-150200.2.2 kernel-livepatch-5_3_18-24_99-default-13-150200.2.2 kernel-livepatch-5_3_18-24_99-default-debuginfo-13-150200.2.2 kernel-livepatch-SLE15-SP2_Update_19-debugsource-16-150200.2.2 kernel-livepatch-SLE15-SP2_Update_20-debugsource-16-150200.2.2 kernel-livepatch-SLE15-SP2_Update_21-debugsource-15-150200.2.2 kernel-livepatch-SLE15-SP2_Update_22-debugsource-14-150200.2.2 kernel-livepatch-SLE15-SP2_Update_23-debugsource-13-150200.2.2 kernel-livepatch-SLE15-SP2_Update_24-debugsource-12-150200.2.2 kernel-livepatch-SLE15-SP2_Update_26-debugsource-7-150200.2.2 kernel-livepatch-SLE15-SP2_Update_27-debugsource-5-150200.2.1 - SUSE Linux Enterprise Module for Live Patching 15-SP2 (ppc64le x86_64): kernel-livepatch-SLE15-SP2_Update_25-debugsource-11-150200.2.2 - SUSE Linux Enterprise Module for Live Patching 15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-150100_197_111-default-7-150100.2.2 kernel-livepatch-4_12_14-150100_197_114-default-4-150100.2.1 kernel-livepatch-4_12_14-150100_197_117-default-2-150100.2.1 kernel-livepatch-4_12_14-197_102-default-13-150100.2.2 kernel-livepatch-4_12_14-197_105-default-9-150100.2.2 kernel-livepatch-4_12_14-197_108-default-8-150100.2.2 - SUSE Linux Enterprise Module for Live Patching 15 (ppc64le x86_64): kernel-livepatch-4_12_14-150000_150_89-default-7-150000.2.2 kernel-livepatch-4_12_14-150000_150_89-default-debuginfo-7-150000.2.2 kernel-livepatch-4_12_14-150000_150_92-default-4-150000.2.1 kernel-livepatch-4_12_14-150000_150_92-default-debuginfo-4-150000.2.1 kernel-livepatch-4_12_14-150000_150_95-default-2-150000.2.1 kernel-livepatch-4_12_14-150000_150_95-default-debuginfo-2-150000.2.1 kernel-livepatch-4_12_14-150_78-default-13-150000.2.2 kernel-livepatch-4_12_14-150_78-default-debuginfo-13-150000.2.2 kernel-livepatch-4_12_14-150_83-default-9-150000.2.2 kernel-livepatch-4_12_14-150_83-default-debuginfo-9-150000.2.2 kernel-livepatch-4_12_14-150_86-default-8-150000.2.2 kernel-livepatch-4_12_14-150_86-default-debuginfo-8-150000.2.2 - SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64): kgraft-patch-4_12_14-122_103-default-14-2.3 kgraft-patch-4_12_14-122_106-default-12-2.3 kgraft-patch-4_12_14-122_110-default-10-2.3 kgraft-patch-4_12_14-122_113-default-9-2.3 kgraft-patch-4_12_14-122_116-default-7-2.3 kgraft-patch-4_12_14-122_121-default-5-2.3 kgraft-patch-4_12_14-122_124-default-4-2.2 kgraft-patch-4_12_14-122_127-default-2-2.2 kgraft-patch-4_12_14-122_88-default-16-2.3 kgraft-patch-4_12_14-122_91-default-16-2.3 kgraft-patch-4_12_14-122_98-default-14-2.3 - SUSE Linux Enterprise Live Patching 12-SP4 (ppc64le s390x x86_64): kgraft-patch-4_12_14-95_102-default-2-2.2 kgraft-patch-4_12_14-95_105-default-2-2.2 kgraft-patch-4_12_14-95_83-default-13-2.3 kgraft-patch-4_12_14-95_88-default-9-2.3 kgraft-patch-4_12_14-95_93-default-8-2.3 kgraft-patch-4_12_14-95_96-default-7-2.3 kgraft-patch-4_12_14-95_99-default-4-2.2 References: https://www.suse.com/security/cve/CVE-2020-36516.html https://www.suse.com/security/cve/CVE-2022-36946.html https://bugzilla.suse.com/1196867 https://bugzilla.suse.com/1201941 . A major SUSE release targeting crucial vulnerabilities within the Linux Kernel, emphasizing improvements in live patching capabilities.. SUSE Linux Enterprise, Live Patching, Kernel Patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for nmap ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1290-1 Rating: moderate References: #1104139 #1133512 Cross-References: CVE-2018-15173 Affected Products: SUSE Linux Enterprise Module for Packagehub Subpackages 15 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for nmap fixes the following issues: Security issue fixed: - CVE-2018-15173: Fixed a remote denial of service attack via a crafted TCP-based service (bsc#1104139). Non-security issue fixed: - Add missing runtime dependency python-xml which prevented zenmap from starting (bsc#1133512). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Packagehub Subpackages 15: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-2019-1290=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-1290=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-1290=1 Package List: - SUSE Linux Enterprise Module for Packagehub Subpackages 15 (aarch64 ppc64le s390x x86_64): nmap-debuginfo-7.70-3.5.1 nmap-debugsource-7.70-3.5.1 nping-7.70-3.5.1 nping-debuginfo-7.70-3.5.1 - SUSE Linux Enterprise Module for OpenBuildservice Development Tools 15 (aarch64 ppc64le s390x x86_64): ncat-7.70-3.5.1 ncat-debuginfo-7.70-3.5.1 ndiff-7.70-3.5.1 nmap-debuginfo-7.70-3.5.1 nmap-debugsource-7.70-3.5.1 nping-7.70-3.5.1 nping-debuginfo-7.70-3.5.1 zenmap-7.70-3.5.1 - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): nmap-7.70-3.5.1 nmap-debuginfo-7.70-3.5.1 nmap-debugsource-7.70-3.5.1 References: https://www.suse.com/security/cve/CVE-2018-15173.html https://bugzilla.suse.com/1104139 https://bugzilla.suse.com/1133512 _______________________________________________ sle-security-updates mailing list
CVE-2018-5391 (FragmentSmack) Juha-Matti Tilli discovered a flaw in the way the Linux kernel handled reassembly of fragmented IPv4 and IPv6 packets. A remote . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4272-1
This SUSE Linux Enterprise 11 Service Pack 1 kernel update brings This SUSE Linux Enterprise 11 Service Pack 1 kernel update brings the kernel to 2.6.32.13. It also contains a security fix and lots of the kernel to 2.6.32.13. It also contains a security fix and lots of other bugfixes. Following security issues were fixed: CVE-2010-1173: The sctp_process_unk_param function in net/sctp/sm_make_chun [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Announcement Package: kernel Announcement ID: SUSE-SA:2010:027 Date: Fri, 02 Jul 2010 08:00:00 +0000 Affected Products: SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise High Availability Extension 11 SP1 Vulnerability Type: remote denial of service CVSS v2 Base Score: 7.1 (AV:N/AC:M/Au:N/C:N/I:N/A:C) SUSE Default Package: yes Cross-References: CVE-2010-1173 Content of This Advisory: 1) Security Vulnerability Resolved: Kernel security and bugfix update Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion This SUSE Linux Enterprise 11 Service Pack 1 kernel update brings the kernel to 2.6.32.13. It also contains a security fix and lots of other bugfixes. Following security issues were fixed: CVE-2010-1173: The sctp_process_unk_param function in net/sctp/sm_make_chunk.c when SCTPis enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid parameters that require a large amount of error data. The update from 2.6.32.12 to 2.6.32.13 might also have contained smaller security fixes. The RPM version of this update is 2.6.32.13-0.4.1. 2) Solution or Work-Around There is no known workaround, please install the update packages. 3) Special Instructions and Notes Please reboot the machine after installing the update. 4) Package Location and Checksums The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv to apply the update, replacing with the filename of the downloaded RPM package. Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web: SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise High Availability Extension 11 SP1 ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file where you saved the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
GDM is the GNOME Display Manager, and is commonly used to provide a graphical login for local users. Upgraded gdm packages are available for Slackware 9.0, 9.1, and -current. These fix two vulnerabilities which could allow a local . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] gdm security update (SSA:2003-300-01) GDM is the GNOME Display Manager, and is commonly used to provide a graphical login for local users. Upgraded gdm packages are available for Slackware 9.0, 9.1, and -current. These fix two vulnerabilities which could allow a local user to crash or freeze gdm, preventing access to the machine until a reboot. Sites using gdm should upgrade, especially sites such as computer labs that use gdm to provide public or semi-public access. More details about these issues may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CAN-2003-0793 https://www.cve.org/CVERecord?id=CAN-2003-0794 Here are the details from the Slackware 9.1 ChangeLog: +--------------------------+ Wed Oct 22 12:10:11 PDT 2003 patches/packages/gdm-2.4.4.5-i486-1.tgz: Upgraded to gdm-2.4.4.5. This fixes a bug which can allow a local user to crash gdm, preventing access until the machine is rebooted. (* Security fix *) +--------------------------+ WHERE TO FIND THE NEW PACKAGES: +-----------------------------+ Updated package for Slackware 9.0: ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/gdm-2.4.1.7-i386-1.tgz Updated package for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/gdm-2.4.4.5-i486-1.tgz Updated package for Slackware -current: MD5 SIGNATURES: +-------------+ Slackware 9.0 package: ba1123ac6d5f56401cd80efcabcd9502 gdm-2.4.1.7-i386-1.tgz Slackware 9.1 package: bb34febec76f6c61f9d3740a95082db8 gdm-2.4.4.5-i486-1.tgz Slackware -current package: bb34febec76f6c61f9d3740a95082db8 gdm-2.4.4.5-i486-1.tgz INSTALLATION INSTRUCTIONS: +------------------------+ First, stopgdm. If you're using runlevel 4 to start gdm, issue the command to change to a console-based runlevel: # telinit 3 Next, upgrade gdm as root: # upgradepkg gdm-2.4.4.5-i486-1.tgz Finally, restart gdm: # telinit 4 +-----+ . GDM has released an urgent security patch for Slackware, addressing local access vulnerabilities. Crucial for every gdm user to implement.. GDM Security Update, Slackware Upgrade, Local Access Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.