Explore top 10 tips to secure your open-source projects now. Read More
×
server: fixed stack exhaustion via unbounded recursion in RPC attribute parsing by enforcing a recursion depth limit (CVE-2026-13757) fixed confusing error message when trying to store an existing cert with trust anchor fixed assert when parsing p11-kit files with value ("). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-695fd36daa 2026-07-12 01:10:38.798644+00:00 -------------------------------------------------------------------------------- Name : p11-kit Product : Fedora 44 Version : 0.26.4 Release : 1.fc44 URL : http://p11-glue.freedesktop.org/p11-kit.html Summary : Library for loading and sharing PKCS#11 modules Description : p11-kit provides a way to load and enumerate PKCS#11 modules, as well as a standard configuration setup for installing PKCS#11 modules in such a way that they're discoverable. -------------------------------------------------------------------------------- Update Information: server: fixed stack exhaustion via unbounded recursion in RPC attribute parsing by enforcing a recursion depth limit (CVE-2026-13757) fixed confusing error message when trying to store an existing cert with trust anchor fixed assert when parsing p11-kit files with value (") fixed numerous memory management issues Build and test fixes Updated translations -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 10 2026 Packit - 0.26.4-1 - Update to 0.26.4 upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494560 - CVE-2026-13757 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494560 [ 2 ] Bug #2498946 - p11-kit-0.26.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2498946 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-695fd36daa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New p11-kit packages are available for Slackware 15.0 and -current to fix a security issue.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] p11-kit (SSA:2026-191-01) New p11-kit packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/p11-kit-0.26.4-i586-1_slack15.0.txz: Upgraded. This update fixes a security issue: server: fixed stack exhaustion via unbounded recursion in RPC attribute parsing by enforcing a recursion depth limit. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-13757 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/p11-kit-0.26.4-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/p11-kit-0.26.4-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/p11-kit-0.26.4-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/p11-kit-0.26.4-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 0ea4b7fff6ae3b2ba9333b0d61189ea3 p11-kit-0.26.4-i586-1_slack15.0.txz Slackware x86_64 15.0 package: ac5289607feefa65ab55ef94a9b7b646 p11-kit-0.26.4-x86_64-1_slack15.0.txz Slackware -current package: 02718b552cbe3ce1a0eeabdabeb926e3 n/p11-kit-0.26.4-i686-1.txz Slackware x86_64 -current package: 04faf2f2c84fc10f785affdb42e85914 n/p11-kit-0.26.4-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg p11-kit-0.26.4-i586-1_slack15.0.txz +-----+ . New p11-kit packages for Slackware address a stack exhaustion issue, enhancing system security and performance.. Slackware p11-kit stack exhaustion security fix. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability and has one security fix can now be installed.. # Security update for rustup Announcement ID: SUSE-SU-2026:2441-1 Release Date: 2026-06-18T07:10:45Z Rating: important References: * bsc#1230032 * bsc#1257902 Cross-References: * CVE-2026-25727 CVSS scores: * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for rustup fixes the following issues * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257902). * rust-shlex: Multiple issues involving quote API (RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2441=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2441=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2441=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2441=1 ## Package List: * openSUSE Leap 15.6 (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150600.10.10.1 * rustup-1.28.2~0-150600.10.10.1 * rustup-debuginfo-1.28.2~0-150600.10.10.1 * Development Tools Module 15-SP7 (aarch64 x86_64) * rustup-1.28.2~0-150600.10.10.1 * rustup-debuginfo-1.28.2~0-150600.10.10.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * rustup-1.28.2~0-150600.10.10.1 * rustup-debuginfo-1.28.2~0-150600.10.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * rustup-1.28.2~0-150600.10.10.1 * rustup-debuginfo-1.28.2~0-150600.10.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25727.html * https://bugzilla.suse.com/show_bug.cgi?id=1230032 * https://bugzilla.suse.com/show_bug.cgi?id=1257902 . An important update for openSUSE resolves a severe stack exhaustion issue in rustup, requiring immediate attention.. openSUSE security,rustup update,stack exhaustion issue. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one security fix can now be installed.. # Security update for rustup Announcement ID: SUSE-SU-2026:2441-1 Release Date: 2026-06-18T07:10:45Z Rating: important References: * bsc#1230032 * bsc#1257902 Cross-References: * CVE-2026-25727 CVSS scores: * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for rustup fixes the following issues * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257902). * rust-shlex: Multiple issues involving quote API (RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2441=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2441=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2441=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2441=1 ## Package List: * openSUSE Leap 15.6 (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150600.10.10.1 * rustup-1.28.2~0-150600.10.10.1 * rustup-debuginfo-1.28.2~0-150600.10.10.1 * Development Tools Module 15-SP7 (aarch64 x86_64) * rustup-1.28.2~0-150600.10.10.1 * rustup-debuginfo-1.28.2~0-150600.10.10.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * rustup-1.28.2~0-150600.10.10.1 * rustup-debuginfo-1.28.2~0-150600.10.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * rustup-1.28.2~0-150600.10.10.1 * rustup-debuginfo-1.28.2~0-150600.10.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25727.html * https://bugzilla.suse.com/show_bug.cgi?id=1230032 * https://bugzilla.suse.com/show_bug.cgi?id=1257902 . An important update for SUSE addressing a vulnerability in rustup, preventing stack exhaustion through date parsing issues.. SUSE rustup patch important security update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for agama ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20753-1 Rating: important References: * bsc#1257930 Cross-References: * CVE-2026-25727 CVSS scores: * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for agama fixes the following issue - CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257930). Changes for agama: - Update "time" crate to version 0.3.47. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-748=1 Package List: - openSUSE Leap 16.0: agama-17+570.fe7244a50-160000.10.1 agama-autoinstall-17+570.fe7244a50-160000.10.1 agama-cli-17+570.fe7244a50-160000.10.1 agama-cli-bash-completion-17+570.fe7244a50-160000.10.2 agama-cli-fish-completion-17+570.fe7244a50-160000.10.2 agama-cli-zsh-completion-17+570.fe7244a50-160000.10.2 agama-openapi-17+570.fe7244a50-160000.10.1 agama-scripts-17+570.fe7244a50-160000.10.1 References: * https://www.suse.com/security/cve/CVE-2026-25727.html . Update for openSUSE fixes critical stack exhaustion issue in agama with CVE-2026-25727 providing important patches.. openSUSE security stack exhaustion update agama CVE-2026-25727. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for librsvg Announcement ID: SUSE-SU-2026:1750-1 Release Date: 2026-05-07T11:52:26Z Rating: important References: * bsc#1257922 Cross-References: * CVE-2026-25727 CVSS scores: * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for librsvg fixes the following issue: * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257922). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1750=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1750=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1750=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patchSUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1750=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1750=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * rsvg-convert-debuginfo-2.57.4-150600.3.8.2 * rsvg-convert-2.57.4-150600.3.8.2 * librsvg-debugsource-2.57.4-150600.3.8.2 * gdk-pixbuf-loader-rsvg-2.57.4-150600.3.8.2 * librsvg-2-2-debuginfo-2.57.4-150600.3.8.2 * gdk-pixbuf-loader-rsvg-debuginfo-2.57.4-150600.3.8.2 * librsvg-devel-2.57.4-150600.3.8.2 * typelib-1_0-Rsvg-2_0-2.57.4-150600.3.8.2 * librsvg-2-2-2.57.4-150600.3.8.2 * openSUSE Leap 15.6 (noarch) * rsvg-thumbnailer-2.57.4-150600.3.8.2 * openSUSE Leap 15.6 (aarch64_ilp32) * librsvg-2-2-64bit-debuginfo-2.57.4-150600.3.8.2 * gdk-pixbuf-loader-rsvg-64bit-debuginfo-2.57.4-150600.3.8.2 * gdk-pixbuf-loader-rsvg-64bit-2.57.4-150600.3.8.2 * librsvg-2-2-64bit-2.57.4-150600.3.8.2 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * librsvg-debugsource-2.57.4-150600.3.8.2 * gdk-pixbuf-loader-rsvg-2.57.4-150600.3.8.2 * librsvg-2-2-debuginfo-2.57.4-150600.3.8.2 * gdk-pixbuf-loader-rsvg-debuginfo-2.57.4-150600.3.8.2 * librsvg-2-2-2.57.4-150600.3.8.2 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * typelib-1_0-Rsvg-2_0-2.57.4-150600.3.8.2 * librsvg-devel-2.57.4-150600.3.8.2 * librsvg-debugsource-2.57.4-150600.3.8.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * librsvg-debugsource-2.57.4-150600.3.8.2 * gdk-pixbuf-loader-rsvg-2.57.4-150600.3.8.2 * librsvg-2-2-debuginfo-2.57.4-150600.3.8.2 * gdk-pixbuf-loader-rsvg-debuginfo-2.57.4-150600.3.8.2 * librsvg-devel-2.57.4-150600.3.8.2 * typelib-1_0-Rsvg-2_0-2.57.4-150600.3.8.2 * librsvg-2-2-2.57.4-150600.3.8.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * librsvg-debugsource-2.57.4-150600.3.8.2 *gdk-pixbuf-loader-rsvg-2.57.4-150600.3.8.2 * librsvg-2-2-debuginfo-2.57.4-150600.3.8.2 * gdk-pixbuf-loader-rsvg-debuginfo-2.57.4-150600.3.8.2 * librsvg-devel-2.57.4-150600.3.8.2 * typelib-1_0-Rsvg-2_0-2.57.4-150600.3.8.2 * librsvg-2-2-2.57.4-150600.3.8.2 ## References: * https://www.suse.com/security/cve/CVE-2026-25727.html * https://bugzilla.suse.com/show_bug.cgi?id=1257922 . A critical update for librsvg on openSUSE resolves a stack exhaustion issue, ensuring better security for users.. librsvg updates, openSUSE security, vulnerabilities resolution, stack exhaustion fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for librsvg Announcement ID: SUSE-SU-2026:21377-1 Release Date: 2026-04-22T10:52:20Z Rating: important References: * bsc#1257922 Cross-References: * CVE-2026-25727 CVSS scores: * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for librsvg fixes the following issue: * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257922). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-622=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-622=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * librsvg-devel-2.60.2-160000.2.1 * gdk-pixbuf-loader-rsvg-2.60.2-160000.2.1 * librsvg-2-2-2.60.2-160000.2.1 * rsvg-convert-2.60.2-160000.2.1 * librsvg-2-2-debuginfo-2.60.2-160000.2.1 * typelib-1_0-Rsvg-2_0-2.60.2-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * rsvg-thumbnailer-2.60.2-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64ppc64le s390x x86_64) * librsvg-devel-2.60.2-160000.2.1 * gdk-pixbuf-loader-rsvg-2.60.2-160000.2.1 * librsvg-2-2-2.60.2-160000.2.1 * rsvg-convert-2.60.2-160000.2.1 * librsvg-2-2-debuginfo-2.60.2-160000.2.1 * typelib-1_0-Rsvg-2_0-2.60.2-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * rsvg-thumbnailer-2.60.2-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25727.html * https://bugzilla.suse.com/show_bug.cgi?id=1257922 . Important update for SUSE addressing librsvg security flaw leading to stack exhaustion. Install recommended patches ASAP.. SUSE security update librsvg important stack exhaustion. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for librsvg Announcement ID: SUSE-SU-2026:21275-1 Release Date: 2026-04-22T10:52:22Z Rating: important References: * bsc#1257922 Cross-References: * CVE-2026-25727 CVSS scores: * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for librsvg fixes the following issue: * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257922). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-622=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * librsvg-2-2-2.60.2-160000.2.1 * gdk-pixbuf-loader-rsvg-2.60.2-160000.2.1 * librsvg-2-2-debuginfo-2.60.2-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25727.html * https://bugzilla.suse.com/show_bug.cgi?id=1257922 . Critical update for librsvg addressing important stack exhaustion issue. Install via zypper for SUSE Linux Micro 6.2.. SUSE Update, Librsvg Security, Stack Exhaustion, SUSE Linux, Important Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.